{"cves":[{"id":"CVE-2017-5987","published":"2017-03-20T00:00:00","updated_at":"2025-08-25T22:35:36.744527+00:00","description":"\nThe sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka\nQuick Emulator) allows local OS guest privileged users to cause a denial of\nservice (infinite loop and QEMU process crash) via vectors involving the\ntransfer mode register during multi block transfer.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/qemu-devel/2017-02/msg02776.html","https://ubuntu.com/security/notices/USN-3261-1","https://ubuntu.com/security/notices/USN-3268-1","https://www.cve.org/CVERecord?id=CVE-2017-5987"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855159"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=8b20aefac4ee8874bb9c8826e4b30e1dc8cd7511","upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=6e86d90352adf6cb08295255220295cf23c4286e","upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=45ba9f761bde329cc5ef276b571bd4f3c41a044e","upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=241999bf4c0dd75d300ceee46f7ad28b3a39fe97"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.33","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.11","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:2.6.1+dfsg-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:2.8+dfsg-3ubuntu2.1","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3268-1","USN-3261-1"],"notices":[{"id":"USN-3268-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2017-04-25T12:01:11.015549","description":"Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU\ndevice. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-10028)\n\nIt was discovered that QEMU incorrectly handled the JAZZ RC4030 device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8667)\n\nJann Horn discovered that QEMU incorrectly handled VirtFS directory\nsharing. A privileged attacker inside the guest could use this issue to\naccess files on the host file system outside of the shared directory and\npossibly escalate their privileges. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. (CVE-2016-9602)\n\nGerd Hoffmann discovered that QEMU incorrectly handled the Cirrus VGA\ndevice when being used with a VNC connection. A privileged attacker inside\nthe guest could use this issue to cause QEMU to crash, resulting in a\ndenial of service, or possibly execute arbitrary code on the host. In the\ndefault installation, when QEMU is used with libvirt, attackers would be\nisolated by the libvirt AppArmor profile. (CVE-2016-9603)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to leak\ncontents of host memory. (CVE-2016-9908)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-9912, CVE-2017-5552,\nCVE-2017-5578)\n\nLi Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2016-9914)\n\nJiang Xin and Wjjzhang discovered that QEMU incorrectly handled SDHCI\ndevice emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2017-5987)\n\nLi Qiang discovered that QEMU incorrectly handled USB OHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to hang, resulting in a denial of service. (CVE-2017-6505)\n","is_hidden":false,"release_packages":{"zesty":[{"name":"qemu","version":"1:2.8+dfsg-3ubuntu2.1","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-misc","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system-s390x","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system-aarch64","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system-x86","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system-sparc","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system-arm","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system-ppc","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"},{"name":"qemu-system-mips","version":"1:2.8+dfsg-3ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2016-10028","CVE-2016-8667","CVE-2016-9602","CVE-2016-9603","CVE-2016-9908","CVE-2016-9912","CVE-2016-9914","CVE-2017-5552","CVE-2017-5578","CVE-2017-5987","CVE-2017-6505"]},{"id":"USN-3261-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2017-04-20T18:33:13.848442","description":"Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU\ndevice. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)\n\nLi Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-10155)\n\nLi Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)\n\nIt was discovered that QEMU incorrectly handled the JAZZ RC4030 device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8667)\n\nIt was discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8669)\n\nIt was discovered that QEMU incorrectly handled the shared rings when used\nwith Xen. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. (CVE-2016-9381)\n\nJann Horn discovered that QEMU incorrectly handled VirtFS directory\nsharing. A privileged attacker inside the guest could use this issue to\naccess files on the host file system outside of the shared directory and\npossibly escalate their privileges. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. (CVE-2016-9602)\n\nGerd Hoffmann discovered that QEMU incorrectly handled the Cirrus VGA\ndevice when being used with a VNC connection. A privileged attacker inside\nthe guest could use this issue to cause QEMU to crash, resulting in a\ndenial of service, or possibly execute arbitrary code on the host. In the\ndefault installation, when QEMU is used with libvirt, attackers would be\nisolated by the libvirt AppArmor profile. (CVE-2016-9603)\n\nIt was discovered that QEMU incorrectly handled the ColdFire Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2016-9776)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to leak\ncontents of host memory. This issue only affected Ubuntu 16.04 LTS and\nUbuntu 16.10. (CVE-2016-9845, CVE-2016-9908)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9846, CVE-2016-9912, CVE-2017-5552,\nCVE-2017-5578, CVE-2017-5857)\n\nLi Qiang discovered that QEMU incorrectly handled the USB redirector. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9907)\n\nLi Qiang discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-9911)\n\nLi Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2016-9913, CVE-2016-9914,\nCVE-2016-9915, CVE-2016-9916)\n\nQinghao Tang, Li Qiang, and Jiangxin discovered that QEMU incorrectly\nhandled the Cirrus VGA device. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2016-9921, CVE-2016-9922)\n\nWjjzhang and Li Qiang discovered that QEMU incorrectly handled the Cirrus\nVGA device. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2615)\n\nIt was discovered that QEMU incorrectly handled the Cirrus VGA device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary code\non the host. In the default installation, when QEMU is used with libvirt,\nattackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2620)\n\nIt was discovered that QEMU incorrectly handled VNC connections. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2017-2633)\n\nLi Qiang discovered that QEMU incorrectly handled the ac97 audio device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5525)\n\nLi Qiang discovered that QEMU incorrectly handled the es1370 audio device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5526)\n\nLi Qiang discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5579)\n\nJiang Xin discovered that QEMU incorrectly handled SDHCI device emulation.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode on the host. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-5667)\n\nLi Qiang discovered that QEMU incorrectly handled the MegaRAID SAS device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5856)\n\nLi Qiang discovered that QEMU incorrectly handled the CCID Card device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5898)\n\nLi Qiang discovered that QEMU incorrectly handled USB xHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2017-5973)\n\nJiang Xin and Wjjzhang discovered that QEMU incorrectly handled SDHCI\ndevice emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2017-5987)\n\nLi Qiang discovered that QEMU incorrectly handled USB OHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to hang, resulting in a denial of service. (CVE-2017-6505)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"}],"yakkety":[{"name":"qemu","version":"1:2.6.1+dfsg-0ubuntu5.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-aarch64","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-arm","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-mips","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-misc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-ppc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-s390x","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-sparc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-x86","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"}]},"type":"USN","cves_ids":["CVE-2016-10028","CVE-2016-10029","CVE-2016-10155","CVE-2016-7907","CVE-2016-8667","CVE-2016-8669","CVE-2016-9381","CVE-2016-9602","CVE-2016-9603","CVE-2016-9776","CVE-2016-9845","CVE-2016-9846","CVE-2016-9907","CVE-2016-9908","CVE-2016-9911","CVE-2016-9912","CVE-2016-9913","CVE-2016-9914","CVE-2016-9915","CVE-2016-9916","CVE-2016-9921","CVE-2016-9922","CVE-2017-2615","CVE-2017-2620","CVE-2017-2633","CVE-2017-5525","CVE-2017-5526","CVE-2017-5552","CVE-2017-5578","CVE-2017-5579","CVE-2017-5667","CVE-2017-5856","CVE-2017-5857","CVE-2017-5898","CVE-2017-5973","CVE-2017-5987","CVE-2017-6505"]}]},{"id":"CVE-2017-5428","published":"2017-03-20T00:00:00","updated_at":"2025-08-25T22:34:16.052220+00:00","description":"\nAn integer overflow in \"createImageBitmap()\" was reported through the\nPwn2Own contest. The fix for this vulnerability disables the experimental\nextensions to the \"createImageBitmap\" API. This function runs in the\ncontent sandbox, requiring a second vulnerability to compromise a user's\ncomputer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox <\n52.0.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2017-08/#CVE-2017-5428","https://ubuntu.com/security/notices/USN-3238-1","https://www.cve.org/CVERecord?id=CVE-2017-5428"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"released","description":"52.0.1+build2-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"52.0.1+build2-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"52.0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"52.0.1+build2-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"52.0.1+build2-0ubuntu0.16.10.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"52.0.1+build2-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3238-1"],"notices":[{"id":"USN-3238-1","title":"Firefox vulnerability","summary":"An integer overflow was discovered in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":[],"published":"2017-03-20T22:12:02.362386","description":"An integer overflow was discovered in Firefox. If a user were tricked in\nto opening a specially crafted website, an attacker could exploit this to\ncause a denial of service via application crash or execute arbitrary code.\n(CVE-2017-5428)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"52.0.1+build2-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"52.0.1+build2-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.12.04.1"}],"trusty":[{"name":"firefox","version":"52.0.1+build2-0ubuntu0.14.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-dev","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-globalmenu","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-af","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-an","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ar","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-as","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ast","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-az","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-be","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bg","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bn","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-br","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bs","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ca","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cak","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cs","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-csb","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cy","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-da","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-de","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-el","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-en","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eo","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-es","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-et","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eu","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fa","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fi","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fr","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fy","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ga","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gd","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gl","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gn","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gu","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-he","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hi","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hr","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hsb","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hu","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hy","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-id","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-is","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-it","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ja","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ka","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kab","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kk","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-km","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kn","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ko","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ku","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lg","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lt","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lv","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mai","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mk","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ml","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mn","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mr","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ms","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nb","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nl","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nn","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nso","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-oc","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-or","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pa","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pl","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pt","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ro","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ru","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-si","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sk","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sl","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sq","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sr","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sv","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sw","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ta","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-te","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-th","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-tr","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uk","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uz","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-vi","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-xh","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hans","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hant","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zu","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-mozsymbols","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-testsuite","version":"52.0.1+build2-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"firefox","version":"52.0.1+build2-0ubuntu0.16.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-dev","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-globalmenu","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-af","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-an","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ar","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-as","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ast","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-az","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-be","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-bg","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-bn","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-br","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-bs","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ca","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-cak","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-cs","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-csb","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-cy","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-da","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-de","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-el","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-en","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-eo","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-es","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-et","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-eu","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-fa","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-fi","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-fr","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-fy","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ga","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-gd","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-gl","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-gn","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-gu","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-he","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-hi","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-hr","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-hsb","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-hu","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-hy","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-id","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-is","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-it","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ja","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ka","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-kab","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-kk","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-km","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-kn","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ko","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ku","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-lg","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-lt","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-lv","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-mai","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-mk","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ml","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-mn","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-mr","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ms","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-nb","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-nl","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-nn","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-nso","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-oc","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-or","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-pa","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-pl","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-pt","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ro","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ru","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-si","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-sk","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-sl","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-sq","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-sr","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-sv","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-sw","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-ta","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-te","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-th","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-tr","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-uk","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-uz","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-vi","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-xh","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-zh-hans","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-zh-hant","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-locale-zu","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-mozsymbols","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"},{"name":"firefox-testsuite","version":"52.0.1+build2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.04.1","pocket":"security"}],"yakkety":[{"name":"firefox","version":"52.0.1+build2-0ubuntu0.16.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"52.0.1+build2-0ubuntu0.16.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/52.0.1+build2-0ubuntu0.16.10.1"}]},"type":"USN","cves_ids":["CVE-2017-5428"]}]},{"id":"CVE-2017-7184","published":"2017-03-19T00:00:00","updated_at":"2026-07-04T07:44:49.982497+00:00","description":"\nThe xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux\nkernel through 4.10.6 does not validate certain size data after an\nXFRM_MSG_NEWAE update, which allows local users to obtain root privileges\nor cause a denial of service (heap-based out-of-bounds access) by\nleveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own\ncompetition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package\n4.8.0.41.52.","ubuntu_description":"\nIt was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.","notes":[{"author":"jdstrand","note":"android kernels (flo, goldfish, grouper, maguro, mako and manta) are\nnot supported on the Ubuntu Touch 14.10 and earlier preview kernels\nlinux-lts-saucy no longer receives official support\nlinux-lts-quantal no longer receives official support"}],"codename":null,"priority":"high","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.eweek.com/security/ubuntu-linux-falls-on-day-1-of-pwn2own-hacking-competition","https://blog.trendmicro.com/results-pwn2own-2017-day-one/","https://twitter.com/thezdi/status/842126074435665920","https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=52b9c816807abd46c285cd8ab183fe93194bfb3f","https://git.kernel.org/linus/677e806da4d916052585301785d847c3b3e6186a","https://git.kernel.org/linus/f843ee6dd019bcece3e74e76ad9df0155655d0df","https://ubuntu.com/security/notices/USN-3250-2","https://ubuntu.com/security/notices/USN-3251-1","https://ubuntu.com/security/notices/USN-3251-2","https://ubuntu.com/security/notices/USN-3249-2","https://ubuntu.com/security/notices/USN-3249-1","https://ubuntu.com/security/notices/USN-3250-1","https://ubuntu.com/security/notices/USN-3248-1","https://www.cve.org/CVERecord?id=CVE-2017-7184"],"bugs":[""],"patches":{"linux":["break-fix: d51d081d65048a7a6f9956a7809c3bb504f3b95d 677e806da4d916052585301785d847c3b3e6186a","break-fix: d51d081d65048a7a6f9956a7809c3bb504f3b95d f843ee6dd019bcece3e74e76ad9df0155655d0df"],"linux-ti-omap4":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-125.168","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-115.162","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-71.92","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.8.0-45.48","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.10.0-19.21","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.10.0-19.21","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1686.113","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1012.21","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1009.9","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-1004.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1009.9","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.8.0-45.48~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.8.0-45.48~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1004.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.13.0-115.162~precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-71.92~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.10.0-1004.6","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1051.58","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.8.0-1032.35","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.10.0-1003.5","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.4.0-1055.59","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1054.58","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.4.0-1055.59","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"4.4.0-1055.59","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1503.130","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3248-1","USN-3250-1","USN-3251-2","USN-3250-2","USN-3251-1","USN-3249-1","USN-3249-2"],"notices":[{"id":"USN-3248-1","title":"Linux kernel vulnerability","summary":"The system could be made to crash or run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-03-29T22:51:31.449973","description":"It was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-ti-omap4","version":"3.2.0-1503.130","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux","version":"3.2.0-125.168","description":"Linux kernel","is_source":true},{"name":"linux-image-powerpc-smp","version":"3.2.0.125.140","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-3.2.0-125-generic-pae","version":"3.2.0-125.168","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-125.168"},{"name":"linux-image-omap4","version":"3.2.0.1503.98","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-3.2.0-125-powerpc64-smp","version":"3.2.0-125.168","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-125.168"},{"name":"linux-image-generic","version":"3.2.0.125.140","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-3.2.0-125-virtual","version":"3.2.0-125.168","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-125.168"},{"name":"linux-image-generic-pae","version":"3.2.0.125.140","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-highbank","version":"3.2.0.125.140","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-3.2.0-125-generic","version":"3.2.0-125.168","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-125.168"},{"name":"linux-image-3.2.0-125-omap","version":"3.2.0-125.168","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-125.168"},{"name":"linux-image-3.2.0-125-powerpc-smp","version":"3.2.0-125.168","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-125.168"},{"name":"linux-image-powerpc64-smp","version":"3.2.0.125.140","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-omap","version":"3.2.0.125.140","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-3.2.0-1503-omap4","version":"3.2.0-1503.130","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1503.130"},{"name":"linux-image-3.2.0-125-highbank","version":"3.2.0-125.168","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-125.168"},{"name":"linux-image-virtual","version":"3.2.0.125.140","is_source":false,"source_link":null,"version_link":null}]},"type":"USN","cves_ids":["CVE-2017-7184"]},{"id":"USN-3250-1","title":"Linux kernel vulnerability","summary":"The system could be made to crash or run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-03-29T22:37:52.682980","description":"It was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.\n\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-115.162","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-115-generic","version":"3.13.0-115.162","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-3.13.0-115-generic-lpae","version":"3.13.0-115.162","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-3.13.0-115-lowlatency","version":"3.13.0-115.162","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-3.13.0-115-powerpc-e500","version":"3.13.0-115.162","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-3.13.0-115-powerpc-e500mc","version":"3.13.0-115.162","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-3.13.0-115-powerpc-smp","version":"3.13.0-115.162","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-3.13.0-115-powerpc64-emb","version":"3.13.0-115.162","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-3.13.0-115-powerpc64-smp","version":"3.13.0-115.162","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"},{"name":"linux-image-extra-3.13.0-115-generic","version":"3.13.0-115.162","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-115.162","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7184"]},{"id":"USN-3251-2","title":"Linux kernel (HWE) vulnerability","summary":"The system could be made to crash or run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-03-30T00:15:03.557486","description":"USN-3251-1 fixed a vulnerability in the Linux kernel for Ubuntu 16.10.\nThis update provides the corresponding updates for the Linux Hardware\nEnablement (HWE) kernel from Ubuntu 16.10 for Ubuntu 16.04 LTS.\n\nIt was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux-hwe","version":"4.8.0-45.48~16.04.1","description":"Linux hardware enablement (HWE) kernel","is_source":true},{"name":"linux-image-4.8.0-45-generic","version":"4.8.0-45.48~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.8.0-45.48~16.04.1","pocket":"security"},{"name":"linux-image-4.8.0-45-generic-lpae","version":"4.8.0-45.48~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.8.0-45.48~16.04.1","pocket":"security"},{"name":"linux-image-4.8.0-45-lowlatency","version":"4.8.0-45.48~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.8.0-45.48~16.04.1","pocket":"security"},{"name":"linux-image-extra-4.8.0-45-generic","version":"4.8.0-45.48~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.8.0-45.48~16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7184"]},{"id":"USN-3250-2","title":"Linux kernel (Trusty HWE) vulnerability","summary":"The system could be made to crash or run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-03-29T23:49:40.767290","description":"USN-3250-1 fixed a vulnerability in the Linux kernel for Ubuntu 14.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu\n12.04 LTS.\n\nIt was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-115.162~precise1","description":"Linux hardware enablement kernel from Trusty for Precise","is_source":true},{"name":"linux-image-3.13.0-115-generic","version":"3.13.0-115.162~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-115.162~precise1"},{"name":"linux-image-generic-lpae-lts-trusty","version":"3.13.0.115.106","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-115.162~precise1"},{"name":"linux-image-3.13.0-115-generic-lpae","version":"3.13.0-115.162~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-115.162~precise1"},{"name":"linux-image-generic-lts-trusty","version":"3.13.0.115.106","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-115.162~precise1"}]},"type":"USN","cves_ids":["CVE-2017-7184"]},{"id":"USN-3251-1","title":"Linux kernel vulnerability","summary":"The system could be made to crash or run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-03-29T23:26:02.672382","description":"It was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.\n","is_hidden":false,"release_packages":{"yakkety":[{"name":"linux-raspi2","version":"4.8.0-1032.35","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux","version":"4.8.0-45.48","description":"Linux kernel","is_source":true},{"name":"linux-image-4.8.0-45-powerpc-e500mc","version":"4.8.0-45.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-45.48"},{"name":"linux-image-powerpc-smp","version":"4.8.0.45.57","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-powerpc-e500mc","version":"4.8.0.45.57","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.8.0-45-generic-lpae","version":"4.8.0-45.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-45.48"},{"name":"linux-image-generic","version":"4.8.0.45.57","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.8.0-45-powerpc-smp","version":"4.8.0-45.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-45.48"},{"name":"linux-image-4.8.0-45-generic","version":"4.8.0-45.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-45.48"},{"name":"linux-image-4.8.0-1032-raspi2","version":"4.8.0-1032.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.8.0-1032.35"},{"name":"linux-image-generic-lpae","version":"4.8.0.45.57","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.8.0-45-lowlatency","version":"4.8.0-45.48","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-45.48"},{"name":"linux-image-lowlatency","version":"4.8.0.45.57","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-raspi2","version":"4.8.0.1032.36","is_source":false,"source_link":null,"version_link":null}]},"type":"USN","cves_ids":["CVE-2017-7184"]},{"id":"USN-3249-1","title":"Linux kernel vulnerability","summary":"The system could be made to crash or run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-03-29T23:10:47.145669","description":"It was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux","version":"4.4.0-71.92","description":"Linux kernel","is_source":true},{"name":"linux-aws","version":"4.4.0-1012.21","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-gke","version":"4.4.0-1009.9","description":"Linux kernel for Google Container Engine (GKE) systems","is_source":true},{"name":"linux-raspi2","version":"4.4.0-1051.58","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-snapdragon","version":"4.4.0-1054.58","description":"Linux kernel for Snapdragon Processors","is_source":true},{"name":"linux-image-4.4.0-1009-gke","version":"4.4.0-1009.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-gke","version_link":"https://launchpad.net/ubuntu/+source/linux-gke/4.4.0-1009.9","pocket":"security"},{"name":"linux-image-4.4.0-1012-aws","version":"4.4.0-1012.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1012.21","pocket":"security"},{"name":"linux-image-4.4.0-1051-raspi2","version":"4.4.0-1051.58","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1051.58","pocket":"security"},{"name":"linux-image-4.4.0-1054-snapdragon","version":"4.4.0-1054.58","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon","version_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1054.58","pocket":"security"},{"name":"linux-image-4.4.0-71-generic","version":"4.4.0-71.92","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"},{"name":"linux-image-4.4.0-71-generic-lpae","version":"4.4.0-71.92","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"},{"name":"linux-image-4.4.0-71-lowlatency","version":"4.4.0-71.92","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc-e500mc","version":"4.4.0-71.92","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc-smp","version":"4.4.0-71.92","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc64-emb","version":"4.4.0-71.92","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc64-smp","version":"4.4.0-71.92","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"},{"name":"linux-image-extra-4.4.0-1009-gke","version":"4.4.0-1009.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gke","version_link":"https://launchpad.net/ubuntu/+source/linux-gke/4.4.0-1009.9","pocket":"security"},{"name":"linux-image-extra-4.4.0-71-generic","version":"4.4.0-71.92","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-71.92","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7184"]},{"id":"USN-3249-2","title":"Linux kernel (Xenial HWE) vulnerability","summary":"The system could be made to crash or run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-03-30T00:02:04.685707","description":"USN-3249-1 fixed a vulnerability in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nIt was discovered that the xfrm framework for transforming packets in the\nLinux kernel did not properly validate data received from user space. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code with administrative privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-xenial","version":"4.4.0-71.92~14.04.1","description":"Linux hardware enablement kernel from Xenial for Trusty","is_source":true},{"name":"linux-image-4.4.0-71-generic","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-71-generic-lpae","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-71-lowlatency","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc-e500mc","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc-smp","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc64-emb","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-71-powerpc64-smp","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"},{"name":"linux-image-extra-4.4.0-71-generic","version":"4.4.0-71.92~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-71.92~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7184"]}]},{"id":"CVE-2014-9938","published":"2017-03-19T00:00:00","updated_at":"2025-08-25T21:31:03.584457+00:00","description":"\ncontrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize\nbranch names in the PS1 variable, allowing a malicious repository to cause\ncode execution.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC: https://github.com/njhartwell/pw3nage\nonly affects 1.8.1+"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3243-1","https://www.cve.org/CVERecord?id=CVE-2014-9938"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1434415"],"patches":{"git":["upstream: https://github.com/git/git/commit/8976500cbbb13270398d3b3e07a17b8cc7bff43f"]},"tags":{},"packages":[{"name":"git","source":"https://ubuntu.com/security/cve?package=git","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=git","debian":"https://tracker.debian.org/pkg/git","statuses":[{"release_codename":"precise","status":"not-affected","description":"1:1.7.9.5-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.9.1-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:2.0.0~rc2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:2.7.4-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3243-1"],"notices":[{"id":"USN-3243-1","title":"Git vulnerability","summary":"Git could be made to run programs as your login if it explored a specially\ncrafted repository.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-23T12:43:36.287667","description":"It was discovered that Git incorrectly sanitized branch names in the PS1\nvariable when configured to display the repository status in the shell\nprompt. If a user were tricked into exploring a malicious repository, a\nremote attacker could use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"git","version":"1:1.9.1-1ubuntu0.4","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-all","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-arch","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-bzr","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-core","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-cvs","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-daemon-run","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-daemon-sysvinit","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-doc","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-el","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-email","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-gui","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-man","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-mediawiki","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"git-svn","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"gitk","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"},{"name":"gitweb","version":"1:1.9.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-9938"]}]},{"id":"CVE-2017-7178","published":"2017-03-18T20:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nCSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation\nmethodology involves (1) hosting a crafted plugin that executes an\narbitrary program from its __init__.py file and (2) causing the victim to\ndownload, install, and enable this plugin.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://git.deluge-torrent.org/deluge/commit/?h=1.3-stable&id=318ab179865e0707d7945edc3a13a464a108d583","http://dev.deluge-torrent.org/wiki/ReleaseNotes/1.3.14","http://git.deluge-torrent.org/deluge/commit/?h=develop&id=11e8957deaf0c76fdfbac62d99c8b6c61cfdddf9","http://seclists.org/fulldisclosure/2017/Mar/6","https://bugs.debian.org/857903","https://www.cve.org/CVERecord?id=CVE-2017-7178"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857903"],"patches":{"deluge":[]},"tags":{},"packages":[{"name":"deluge","source":"https://ubuntu.com/security/cve?package=deluge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=deluge","debian":"https://tracker.debian.org/pkg/deluge","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.13+git20161130.48cedf63-2, 1.3.14","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.3.15-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7177","published":"2017-03-18T20:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nSuricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by\nlack of a check for the IP protocol during fragment matching.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://redmine.openinfosecfoundation.org/issues/2019","https://github.com/inliniac/suricata/commit/4a04f814b15762eb446a5ead4d69d021512df6f8","https://www.cve.org/CVERecord?id=CVE-2017-7177"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856649"],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.2.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10253","published":"2017-03-18T00:00:00","updated_at":"2025-08-25T21:53:10.076687+00:00","description":"\nAn issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled\nregular expressions is vulnerable to a heap overflow. Regular expressions\nusing a malformed extpattern can indirectly specify an offset that is used\nas an array index. This ordinal permits arbitrary regions within the\nerts_alloc arena to be both read and written to.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream migrated to a new pcre version instead of using the\nproposed patch"}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/erlang/otp/pull/1108","https://ubuntu.com/security/notices/USN-3571-1","https://www.cve.org/CVERecord?id=CVE-2016-10253"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858313"],"patches":{"erlang":[]},"tags":{},"packages":[{"name":"erlang","source":"https://ubuntu.com/security/cve?package=erlang","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=erlang","debian":"https://tracker.debian.org/pkg/erlang","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:20.0.4+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:18.3-dfsg-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:19.2.1+dfsg-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3571-1"],"notices":[{"id":"USN-3571-1","title":"Erlang vulnerabilities","summary":"Several security issues were fixed in Erlang.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2018-02-14T14:54:29.756770","description":"It was discovered that the Erlang FTP module incorrectly handled certain\nCRLF sequences. A remote attacker could possibly use this issue to inject\narbitrary FTP commands. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2014-1693)\n\nIt was discovered that Erlang incorrectly checked CBC padding bytes. A\nremote attacker could possibly use this issue to perform a padding oracle\nattack and decrypt traffic. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2015-2774)\n\nIt was discovered that Erlang incorrectly handled certain regular\nexpressions. A remote attacker could possibly use this issue to cause\nErlang to crash, resulting in a denial of service, or execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10253)\n\nHanno Böck, Juraj Somorovsky and Craig Young discovered that the Erlang\notp TLS server incorrectly handled error reporting. A remote attacker could\npossibly use this issue to perform a variation of the Bleichenbacher attack\nand decrypt traffic or sign messages. (CVE-2017-1000385)\n","is_hidden":false,"release_packages":{"artful":[{"name":"erlang","version":"1:20.0.4+dfsg-1ubuntu1.1","description":"Concurrent, real-time, distributed functional language","is_source":true},{"name":"erlang","version":"1:20.0.4+dfsg-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:20.0.4+dfsg-1ubuntu1.1"}],"trusty":[{"name":"erlang","version":"1:16.b.3-dfsg-1ubuntu2.2","description":"Concurrent, real-time, distributed functional language","is_source":true},{"name":"erlang","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-appmon","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-asn1","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-base","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-base-hipe","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-common-test","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-corba","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-crypto","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-debugger","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-dev","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-dialyzer","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-diameter","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-doc","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-edoc","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-eldap","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-erl-docgen","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-et","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-eunit","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-examples","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-gs","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ic","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ic-java","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-inets","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-jinterface","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-manpages","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-megaco","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-mnesia","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-mode","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-nox","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-observer","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-odbc","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-os-mon","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-parsetools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-percept","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-pman","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-public-key","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-reltool","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-runtime-tools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-snmp","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-src","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ssh","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ssl","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-syntax-tools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-test-server","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-toolbar","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-tools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-tv","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-typer","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-webtool","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-x11","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-xmerl","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"}],"xenial":[{"name":"erlang","version":"1:18.3-dfsg-1ubuntu3.1","description":"Concurrent, real-time, distributed functional language","is_source":true},{"name":"erlang","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-asn1","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-base","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-base-hipe","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-common-test","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-corba","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-crypto","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-debugger","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-dev","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-dialyzer","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-diameter","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-doc","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-edoc","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-eldap","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-erl-docgen","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-et","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-eunit","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-examples","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-gs","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ic","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ic-java","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-inets","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-jinterface","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-manpages","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-megaco","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-mnesia","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-mode","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-nox","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-observer","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-odbc","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-os-mon","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-parsetools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-percept","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-public-key","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-reltool","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-runtime-tools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-snmp","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-src","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ssh","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ssl","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-syntax-tools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-test-server","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-tools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-typer","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-webtool","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-wx","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-x11","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-xmerl","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-1693","CVE-2015-2774","CVE-2016-10253","CVE-2017-1000385"]}]},{"id":"CVE-2015-7313","published":"2017-03-17T14:59:00","updated_at":"2025-09-15T15:41:25.712948+00:00","description":"\nLibTIFF before 4.0.7 allows remote attackers to cause a denial of service\n(memory consumption and crash) via a crafted tiff file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"as of 2021-02-24, no upstream fix"},{"author":"sbeattie","note":"likely fixed in upstream 4.0.7 release\nreproducer in oss-security post"},{"author":"ccdm94","note":"bionic and later are not-affected and the issue\nis not reproducible in trusty (no huge reallocs\nare made, as would be expected), and is also\nnot reproducible in xenial (no reallocs made\nat all, according to ltrace output) with the\nPOC file provided in the oss-security post.\nNo upstream patch was identified after analysis\nof the libtiff changelog file, as well as the\nchange history for the tiffdither code. Since\nthis is a 2015 issue, trusty and xenial will\nbe marked as ignored."}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=144284777006804&w=2","https://www.cve.org/CVERecord?id=CVE-2015-7313"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=800124","http://bugzilla.maptools.org/show_bug.cgi?id=2524 (old)","https://gitlab.com/libtiff/libtiff/issues/59"],"patches":{"tiff":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0.9-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.0.9-6ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.1.0+git191117-2build1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.3.0-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.1.0+git191117-2build1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.1.0+git191117-2build1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.3.0-6","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4645","published":"2017-03-17T14:59:00","updated_at":"2025-08-25T21:40:13.453179+00:00","description":"\nInteger overflow in the read_fragment_table_4 function in unsquash-4.c in\nSquashfs and sasquatch allows remote attackers to cause a denial of service\n(application crash) via a crafted input, which triggers a stack-based\nbuffer overflow.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"xenial got updated to 1:4.3-3ubuntu2.16.04.3 fixing this (LP: #1785499)"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/06/18/10","https://www.cve.org/CVERecord?id=CVE-2015-4645"],"bugs":["https://bugs.launchpad.net/bugs/1785499"],"patches":{"squashfs-tools":[]},"tags":{},"packages":[{"name":"squashfs-tools","source":"https://ubuntu.com/security/cve?package=squashfs-tools","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=squashfs-tools","debian":"https://tracker.debian.org/pkg/squashfs-tools","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:4.3-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:4.3-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:4.3-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:4.3-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:4.3-3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9852","published":"2017-03-17T14:59:00","updated_at":"2025-08-25T21:30:32.150733+00:00","description":"\ndistribute-cache.c in ImageMagick re-uses objects after they have been\ndestroyed, which allows remote attackers to have unspecified impact via\nunspecified vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0052-Fixed-usage-of-object-after-it-has-been-destroyed-an.patch"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-9852"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773834"],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-4","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"8:6.8.9.9-5ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8:6.8.9.9-7ubuntu5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8:6.8.9.9-7ubuntu8","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6969","published":"2017-03-17T09:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nreadelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read\nwhile processing corrupt RL78 binaries. The vulnerability can trigger\nprogram crashes. It may lead to an information leak as well.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/03/16/8","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-6969"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=21156"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=b814a36d3440de95f2ac6eaa4fc7935c322ea456","upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=43a444f9c5bfd44b4304eafd78338e21d54bea14"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.28.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-6967","published":"2017-03-17T09:59:00","updated_at":"2025-08-25T22:36:44.777789+00:00","description":"\nxrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect\nlocation, leading to PAM session modules not being properly initialized,\nwith a potential consequence of incorrect configurations or elevation of\nprivileges, aka a pam_limits.so bypass.","ubuntu_description":"\nIt was discovered that PAM incorrectly initialized session modules. This\ncould potentially bypass enforcement of limits.","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.launchpad.net/ubuntu/+source/xrdp/+bug/1672742","https://github.com/neutrinolabs/xrdp/issues/350","https://github.com/neutrinolabs/xrdp/pull/694","https://github.com/neutrinolabs/xrdp/pull/696","https://www.cve.org/CVERecord?id=CVE-2017-6967","https://ubuntu.com/security/notices/USN-4815-1"],"bugs":[""],"patches":{"xrdp":[]},"tags":{},"packages":[{"name":"xrdp","source":"https://ubuntu.com/security/cve?package=xrdp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xrdp","debian":"https://tracker.debian.org/pkg/xrdp","statuses":[{"release_codename":"groovy","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.9.5-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.5.0-2+deb7u1build0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.1-9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.6.1-2ubuntu0.3+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.6.0-1ubuntu0.1+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4815-1"],"notices":[{"id":"USN-4815-1","title":"xrdp vulnerabilities","summary":"Several security issues were fixed in xrdp.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:50:35.291826","description":"It was discovered that xrdp did not properly validate certain input in the\nsession manager. A local attacker could possibly use this issue to cause a\ndenial of service or other unspecified impact. (CVE-2017-16927)\n\nIt was discovered that xrdp did not properly initialize PAM session\nmodules. A remote attacker could possibly use this issue to escalate\nprivileges. (CVE-2017-6967)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.0-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm1","description":"Remote Desktop Protocol (RDP) server","is_source":true},{"name":"xrdp","version":"0.6.1-2ubuntu0.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xrdp","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-6967","CVE-2017-16927"]}]},{"id":"CVE-2017-6966","published":"2017-03-17T09:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nreadelf in GNU Binutils 2.28 has a use-after-free (specifically\nread-after-free) error while processing multiple, relocated sections in an\nMSP430 binary. This is caused by mishandling of an invalid symbol index,\nand mishandling of state across invocations.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-6966"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=21139"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f84ce13b6708801ca1d6289b7c4003e2f5a6d7f9"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"upstream","status":"released","description":"2.28-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-6965","published":"2017-03-17T09:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nreadelf in GNU Binutils 2.28 writes to illegal addresses while processing\ncorrupt input files containing symbol-difference relocations, leading to a\nheap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-6965"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=21137"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=03f7786e2f440b9892b1c34a58fb26222ce1b493"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.28-3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-6962","published":"2017-03-17T09:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nAn issue was discovered in apng2gif 1.7. There is an integer overflow\nresulting in a heap-based buffer overflow. This is related to the\nread_chunk function making an unchecked addition of 12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854447","https://www.cve.org/CVERecord?id=CVE-2017-6962"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854447"],"patches":{"apng2gif":[]},"tags":{},"packages":[{"name":"apng2gif","source":"https://ubuntu.com/security/cve?package=apng2gif","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apng2gif","debian":"https://tracker.debian.org/pkg/apng2gif","statuses":[{"release_codename":"hirsute","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.8-0.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6961","published":"2017-03-17T09:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nAn issue was discovered in apng2gif 1.7. There is improper sanitization of\nuser input causing huge memory allocations, resulting in a crash. This is\nrelated to the read_chunk function using the pChunk->size value (within the\nPNG file) to determine the amount of memory to allocate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854441","https://www.cve.org/CVERecord?id=CVE-2017-6961"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854441"],"patches":{"apng2gif":[]},"tags":{},"packages":[{"name":"apng2gif","source":"https://ubuntu.com/security/cve?package=apng2gif","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apng2gif","debian":"https://tracker.debian.org/pkg/apng2gif","statuses":[{"release_codename":"hirsute","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.8-0.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6960","published":"2017-03-17T09:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nAn issue was discovered in apng2gif 1.7. There is an integer overflow\nresulting in a heap-based buffer over-read, related to the load_apng\nfunction and the imagesize variable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854367","https://ubuntu.com/security/notices/USN-4513-1","https://www.cve.org/CVERecord?id=CVE-2017-6960"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854367"],"patches":{"apng2gif":[]},"tags":{},"packages":[{"name":"apng2gif","source":"https://ubuntu.com/security/cve?package=apng2gif","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apng2gif","debian":"https://tracker.debian.org/pkg/apng2gif","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5-1+deb7u1, 1.8-0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.5-3+deb8u1build0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.8-0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4513-1"],"notices":[{"id":"USN-4513-1","title":"apng2gif vulnerability","summary":"apng2gif could be made to expose sensitive information if it opened a\nspecifically crafted APNG file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-09-17T13:35:32.715835","description":"Dileep Kumar Jallepalli discovered that apng2gif incorrectly handled\nloading APNG files. An attacker could exploit this with a crafted APNG\nfile to access sensitive information. (CVE-2017-6960)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"apng2gif","version":"1.5-3+deb8u1build0.16.04.1","description":"tool for converting APNG images to animated GIF format","is_source":true},{"name":"apng2gif","version":"1.5-3+deb8u1build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apng2gif","version_link":"https://launchpad.net/ubuntu/+source/apng2gif/1.5-3+deb8u1build0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6960"]}]},{"id":"CVE-2017-6952","published":"2017-03-16T21:59:00","updated_at":"2025-08-25T22:36:44.777789+00:00","description":"\nInteger overflow in the cs_winkernel_malloc function in winkernel_mm.c in\nCapstone 3.0.4 and earlier allows attackers to cause a denial of service\n(heap-based buffer overflow in a kernel driver) or possibly have\nunspecified other impact via a large value.","ubuntu_description":"","notes":[{"author":"ratliff","note":"Windows-specific"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/aquynh/capstone/commit/6fe86eef621b9849f51a5e1e5d73258a93440403","https://www.cve.org/CVERecord?id=CVE-2017-6952"],"bugs":[""],"patches":{"capstone":[]},"tags":{},"packages":[{"name":"capstone","source":"https://ubuntu.com/security/cve?package=capstone","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=capstone","debian":"https://tracker.debian.org/pkg/capstone","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6949","published":"2017-03-16T17:59:00","updated_at":"2025-08-26T12:01:19.317603+00:00","description":"\nAn issue was discovered in CHICKEN Scheme through 4.12.0. When using a\nnonstandard CHICKEN-specific extension to allocate an SRFI-4 vector in\nunmanaged memory, the vector size would be used in unsanitised form as an\nargument to malloc(). With an unexpected size, the impact may have been a\nsegfault or buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/chicken-announce/2017-03/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2017-6949"],"bugs":[""],"patches":{"chicken":[]},"tags":{},"packages":[{"name":"chicken","source":"https://ubuntu.com/security/cve?package=chicken","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chicken","debian":"https://tracker.debian.org/pkg/chicken","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12.0-0.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5617","published":"2017-03-16T15:59:00","updated_at":"2025-08-25T22:34:58.789019+00:00","description":"\nThe SVG Salamander (aka svgSalamander) library, when used in a web\napplication, allows remote attackers to conduct server-side request forgery\n(SSRF) attacks via an xlink:href attribute in an SVG file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/blackears/svgSalamander/issues/11","http://www.openwall.com/lists/oss-security/2017/01/27/3","https://www.cve.org/CVERecord?id=CVE-2017-5617"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853134"],"patches":{"svgsalamander":[]},"tags":{},"packages":[{"name":"svgsalamander","source":"https://ubuntu.com/security/cve?package=svgsalamander","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=svgsalamander","debian":"https://tracker.debian.org/pkg/svgsalamander","statuses":[{"release_codename":"precise","status":"released","description":"0~svn95-1+deb8u1build0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0~svn95-1+deb8u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0~svn95-1+deb8u1build0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.1.1+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":57780,"limit":20,"total_results":79316}