{"cves":[{"id":"CVE-2016-9394","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows\nremote attackers to cause a denial of service (assertion failure) via a\ncrafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same commit as CVE-2016-9392"}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00016-jasper-assert-jas_matrix_t (testcase)","http://www.openwall.com/lists/oss-security/2016/11/17/1","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9394"],"bugs":[""],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/f7038068550fba0e41e1d0c355787f1dcd5bf330"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9393","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe jpc_pi_nextrpcl function in jpc_t2cod.c in JasPer before 1.900.17\nallows remote attackers to cause a denial of service (assertion failure)\nvia a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same commit as CVE-2016-9392"}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00013-jasper-assert-jpc_pi_nextrpcl (testcase)","http://www.openwall.com/lists/oss-security/2016/11/17/1","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9393"],"bugs":[""],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/f7038068550fba0e41e1d0c355787f1dcd5bf330"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9392","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe calcstepsizes function in jpc_dec.c in JasPer before 1.900.17 allows\nremote attackers to cause a denial of service (assertion failure) via a\ncrafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/17/1","https://github.com/asarubbo/poc/blob/master/00012-jasper-assert-calcstepsizes (testcase)","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9392"],"bugs":["https://github.com/mdadams/jasper/issues/57"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/f7038068550fba0e41e1d0c355787f1dcd5bf330"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9391","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe jpc_bitstream_getbits function in jpc_bs.c in JasPer before 2.0.10\nallows remote attackers to cause a denial of service (assertion failure)\nvia a very large integer.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00014-jasper-assert-jpc_bitstream_getbits (testcase)","http://www.openwall.com/lists/oss-security/2016/11/17/1","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9391"],"bugs":["https://github.com/mdadams/jasper/issues/59"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/1e84674d95353c64e5c4c0e7232ae86fd6ea813b"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9390","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows\nremote attackers to cause a denial of service (assertion failure) via a\ncrafted image file.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00007-jasper-assert-jas_matrix_t (testcase)","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9390"],"bugs":["https://github.com/mdadams/jasper/issues/49","https://github.com/mdadams/jasper/issues/53"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/ba2b9d000660313af7b692542afbd374c5685865"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9389","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe jpc_irct and jpc_iict functions in jpc_mct.c in JasPer before 1.900.14\nallow remote attackers to cause a denial of service (assertion failure).","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00006-jasper-assert-jpc_irct (testcase)","https://github.com/asarubbo/poc/blob/master/00008-jasper-assert-jpc_iict (testcase)","http://www.openwall.com/lists/oss-security/2016/11/17/1","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9389"],"bugs":["https://github.com/mdadams/jasper/issues/52","https://github.com/mdadams/jasper/issues/55"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/dee11ec440d7908d1daf69f40a3324b27cf213ba"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9388","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows\nremote attackers to cause a denial of service (assertion failure) via a\ncrafted image file.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/17/1","https://github.com/asarubbo/poc/blob/master/00005-jasper-assert-ras_getcmap (testcase)","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9388"],"bugs":[""],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/411a4068f8c464e883358bf403a3e25158863823"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9387","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:13:39.965445+00:00","description":"\nInteger overflow in the jpc_dec_process_siz function in\nlibjasper/jpc/jpc_dec.c in JasPer before 1.900.13 allows remote attackers\nto have unspecified impact via a crafted file, which triggers an assertion\nfailure.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00003-jasper-assert-jas_matrix_t (testcase)","http://www.openwall.com/lists/oss-security/2016/11/17/1","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-9387"],"bugs":["https://github.com/mdadams/jasper/issues/49","https://github.com/mdadams/jasper/issues/53","https://github.com/mdadams/jasper/issues/119"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/d91198abd00fc435a397fe6bad906a4c1748e9cf","upstream: https://github.com/mdadams/jasper/commit/a712a2041085e7cd5f2b153e1532ac2a2954ffaa"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-8887","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T22:12:55.289561+00:00","description":"\nThe jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before\n1.900.10 allows remote attackers to cause a denial of service (NULL pointer\ndereference).","ubuntu_description":"","notes":[{"author":"sbeattie","note":"first fix was incomplete, need second fix as well"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/10/18/jasper-null-pointer-dereference-in-jp2_colr_destroy-jp2_cod-c","https://blogs.gentoo.org/ago/2016/10/23/jasper-null-pointer-dereference-in-jp2_colr_destroy-jp2_cod-c-incomplete-fix-for-cve-2016-8887","https://ubuntu.com/security/notices/USN-3693-1","https://www.cve.org/CVERecord?id=CVE-2016-8887"],"bugs":["https://github.com/mdadams/jasper/issues/34","https://github.com/mdadams/jasper/issues/45"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/e24bdc716c3327b067c551bc6cfb97fd2370358d","upstream: https://github.com/mdadams/jasper/commit/bdfe95a6e81ffb4b2fad31a76b57943695beed20"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.900.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-10255","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T21:53:10.076687+00:00","description":"\nThe __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils\nbefore 0.168 allows remote attackers to cause a denial of service (crash)\nvia a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a\nmemory allocation failure.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/11/04/elfutils-memory-allocation-failure-in-__libelf_set_rawdata_wrlock-elf_getdata-c/","https://ubuntu.com/security/notices/USN-3670-1","https://www.cve.org/CVERecord?id=CVE-2016-10255"],"bugs":[""],"patches":{"elfutils":["upstream: https://sourceware.org/git/?p=elfutils.git;a=commitdiff;h=09ec02ec7f7e6913d10943148e2a898264345b07"]},"tags":{},"packages":[{"name":"elfutils","source":"https://ubuntu.com/security/cve?package=elfutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=elfutils","debian":"https://tracker.debian.org/pkg/elfutils","statuses":[{"release_codename":"artful","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.158-0ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.165-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"0.168-0.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3670-1"],"notices":[{"id":"USN-3670-1","title":"elfutils vulnerabilities","summary":"elfutils could be made to crash or consume resources if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-05T14:13:40.406632","description":"Agostino Sarubbo discovered that elfutils incorrectly handled certain\nmalformed ELF files. If a user or automated system were tricked into\nprocessing a specially crafted ELF file, elfutils could be made to crash or\nconsume resources, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"elfutils","version":"0.158-0ubuntu5.3","description":"collection of utilities to handle ELF objects","is_source":true},{"name":"elfutils","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libasm-dev","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libasm1","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libdw-dev","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libdw1","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libelf-dev","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libelf1","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"}],"xenial":[{"name":"elfutils","version":"0.165-3ubuntu1.1","description":"collection of utilities to handle ELF objects","is_source":true},{"name":"elfutils","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libasm-dev","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libasm1","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libdw-dev","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libdw1","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libelf-dev","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libelf1","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10254","CVE-2016-10255","CVE-2017-7607","CVE-2017-7608","CVE-2017-7609","CVE-2017-7610","CVE-2017-7611","CVE-2017-7612","CVE-2017-7613"]}]},{"id":"CVE-2016-10254","published":"2017-03-23T00:00:00","updated_at":"2025-08-25T21:53:10.076687+00:00","description":"\nThe allocate_elf function in common.h in elfutils before 0.168 allows\nremote attackers to cause a denial of service (crash) via a crafted ELF\nfile, which triggers a memory allocation failure.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/11/04/elfutils-memory-allocation-failure-in-allocate_elf-common-h/","https://ubuntu.com/security/notices/USN-3670-1","https://www.cve.org/CVERecord?id=CVE-2016-10254"],"bugs":[""],"patches":{"elfutils":["upstream: https://sourceware.org/git/?p=elfutils.git;a=commitdiff;h=191000fdedba3fafe4d5b8cddad3f3318b49c3fb"]},"tags":{},"packages":[{"name":"elfutils","source":"https://ubuntu.com/security/cve?package=elfutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=elfutils","debian":"https://tracker.debian.org/pkg/elfutils","statuses":[{"release_codename":"artful","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.158-0ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.165-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"0.168-0.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"0.168-0.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3670-1"],"notices":[{"id":"USN-3670-1","title":"elfutils vulnerabilities","summary":"elfutils could be made to crash or consume resources if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-05T14:13:40.406632","description":"Agostino Sarubbo discovered that elfutils incorrectly handled certain\nmalformed ELF files. If a user or automated system were tricked into\nprocessing a specially crafted ELF file, elfutils could be made to crash or\nconsume resources, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"elfutils","version":"0.158-0ubuntu5.3","description":"collection of utilities to handle ELF objects","is_source":true},{"name":"elfutils","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libasm-dev","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libasm1","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libdw-dev","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libdw1","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libelf-dev","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"},{"name":"libelf1","version":"0.158-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.158-0ubuntu5.3","pocket":"security"}],"xenial":[{"name":"elfutils","version":"0.165-3ubuntu1.1","description":"collection of utilities to handle ELF objects","is_source":true},{"name":"elfutils","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libasm-dev","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libasm1","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libdw-dev","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libdw1","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libelf-dev","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"},{"name":"libelf1","version":"0.165-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/elfutils","version_link":"https://launchpad.net/ubuntu/+source/elfutils/0.165-3ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10254","CVE-2016-10255","CVE-2017-7607","CVE-2017-7608","CVE-2017-7609","CVE-2017-7610","CVE-2017-7611","CVE-2017-7612","CVE-2017-7613"]}]},{"id":"CVE-2017-7227","published":"2017-03-22T16:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nGNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer\noverflow while processing a bogus input script, leading to a program crash.\nThis relates to lack of '\\0' termination of a name field in ldlex.l.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-7227"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=20906"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=406bd128dba2a59d0736839fc87a59bce319076c"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.27.51.20161212-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-7226","published":"2017-03-22T16:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nThe pe_ILF_object_p function in the Binary File Descriptor (BFD) library\n(aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a\nheap-based buffer over-read of size 4049 because it uses the strlen\nfunction instead of strnlen, leading to program crashes in several\nutilities such as addr2line, size, and strings. It could lead to\ninformation disclosure as well.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-7226"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=20905"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=fa6631b4eecfcca00c13b9594e6336dffd40982f"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.27.51.20161212-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-7225","published":"2017-03-22T16:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nThe find_nearest_line function in addr2line in GNU Binutils 2.28 does not\nhandle the case where the main file name and the directory name are both\nempty, triggering a NULL pointer dereference and an invalid write, and\nleading to a program crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-7225"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=20891"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=50455f1ab2935f7321215dfa681745c9b1cb5b19"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.27.51.20161201-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-7224","published":"2017-03-22T16:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nThe find_nearest_line function in objdump in GNU Binutils 2.28 is\nvulnerable to an invalid write (of size 1) while disassembling a corrupt\nbinary that contains an empty function name, leading to a program crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-7224"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=20892"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=e82ab856bb4689330c29fb9f1c57a8555b26380e"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.27.51.20161201-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-7223","published":"2017-03-22T16:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nGNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer\noverflow (of size 1) while attempting to unget an EOF character from the\ninput stream, potentially leading to a program crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-7223"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=20898"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=69ace2200106348a1b00d509a6a234337c104c17"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.27.51.20161212-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2014-9832","published":"2017-03-22T14:59:00","updated_at":"2025-08-25T21:30:22.334710+00:00","description":"\nHeap overflow in ImageMagick 6.8.9-9 via a crafted pcx file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0030-Fix-heap-overflow-in-pcx-file-psd-pict-and-wpf-files.patch"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-9832"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773834"],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-4","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"8:6.8.9.9-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8:6.8.9.9-7ubuntu5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8:6.8.9.9-7ubuntu8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7222","published":"2017-03-22T05:59:00","updated_at":"2025-08-25T22:37:18.497515+00:00","description":"\nA cross-site scripting (XSS) vulnerability in MantisBT before 2.1.1 allows\nremote attackers to inject arbitrary HTML or JavaScript (if MantisBT's CSP\nsettings permit it) by modifying 'window_title' in the application\nconfiguration. This requires privileged access to MantisBT configuration\nmanagement pages (i.e., administrator access rights) or altering the system\nconfiguration file (config_inc.php).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://github.com/mantisbt/mantisbt/commit/a85b0b96c8ebe3e010d0d016cf88ab3c8bfc196a","https://mantisbt.org/bugs/view.php?id=22266","https://www.cve.org/CVERecord?id=CVE-2017-7222"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7214","published":"2017-03-21T18:59:00","updated_at":"2025-08-25T22:37:18.497515+00:00","description":"\nAn issue was discovered in exception_wrapper.py in OpenStack Nova 13.x\nthrough 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy\nnotification exception contexts appearing in ERROR level logs may include\nsensitive information such as account passwords and authorization tokens.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"issue was introduced in Mitaka"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-7214"],"bugs":["https://launchpad.net/bugs/1673569"],"patches":{"nova":[]},"tags":{},"packages":[{"name":"nova","source":"https://ubuntu.com/security/cve?package=nova","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nova","debian":"https://tracker.debian.org/pkg/nova","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:13.1.4-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2:15.0.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7210","published":"2017-03-21T06:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nobjdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer\nover-reads (of size 1 and size 8) while handling corrupt STABS enum type\nstrings in a crafted object file, leading to program crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-7210"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=21157","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858324"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=a2dea0b20bc66a4c287c3c50002b8c3b3e9d953a"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.28.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]}],"offset":57740,"limit":20,"total_results":79316}