{"cves":[{"id":"CVE-2017-6874","published":"2017-03-14T09:59:00","updated_at":"2026-07-04T07:44:10.223702+00:00","description":"\nRace condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows\nlocal users to cause a denial of service (use-after-free and system crash)\nor possibly have unspecified other impact via crafted system calls that\nleverage certain decrement behavior that causes incorrect interaction\nbetween put_ucounts and get_ucounts.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"android kernels (flo, goldfish, grouper, maguro, mako and manta) are\nnot supported on the Ubuntu Touch 14.10 and earlier preview kernels\nlinux-lts-saucy no longer receives official support\nlinux-lts-quantal no longer receives official support"}],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=040757f738e13caaa9c5078bca79aa97e11dde88","https://github.com/torvalds/linux/commit/040757f738e13caaa9c5078bca79aa97e11dde88","https://www.cve.org/CVERecord?id=CVE-2017-6874"],"bugs":[""],"patches":{"linux":["break-fix: f6b2db1a3e8d141dd144df58900fb0444d5d7c53 040757f738e13caaa9c5078bca79aa97e11dde88"],"linux-ti-omap4":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.10.0-15.17","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-27.30~16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-27.30~16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.10.0-1003.5","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-8747","published":"2017-03-14T09:59:00","updated_at":"2026-09-11T07:05:53.743893+00:00","description":"\nAn information disclosure issue was discovered in Apache Tomcat 8.5.7 to\n8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations.\nHttp11InputBuffer.java allows remote attackers to read data that was\nintended to be associated with a different request.","ubuntu_description":"","notes":[{"author":"ratliff","note":"introduced in r1766968"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://svn.apache.org/r1774166","http://svn.apache.org/viewvc?view=revision&revision=1774161","http://svn.apache.org/viewvc?view=revision&revision=1774166","http://tomcat.apache.org/security-8.html","http://tomcat.apache.org/security-9.html","http://svn.apache.org/r1774166","https://www.cve.org/CVERecord?id=CVE-2016-8747"],"bugs":[""],"patches":{"tomcat8":[]},"tags":{},"packages":[{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.5.9-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6839","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:40.010483+00:00","description":"\nInteger overflow in modules/MSADPCM.cpp in Audio File Library (aka\naudiofile) 0.3.6 allows remote attackers to cause a denial of service\n(crash) via a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-multiple-ubsan-crashes/","http://www.openwall.com/lists/oss-security/2017/03/13/9","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6839"],"bugs":["https://github.com/mpruett/audiofile/issues/41","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c","upstream: https://github.com/antlarr/audiofile/commit/ce536d707b8e2a26baca77320398c45238224ca7"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6838","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:40.010483+00:00","description":"\nInteger overflow in sfcommands/sfconvert.c in Audio File Library (aka\naudiofile) 0.3.6 allows remote attackers to cause a denial of service\n(crash) via a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-multiple-ubsan-crashes/","http://www.openwall.com/lists/oss-security/2017/03/13/9","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6838"],"bugs":["https://github.com/mpruett/audiofile/issues/41","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c","upstream: https://github.com/antlarr/audiofile/commit/ce536d707b8e2a26baca77320398c45238224ca7"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6837","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nWAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote\nattackers to cause a denial of service (crash) via vectors related to a\nlarge number of coefficients.","ubuntu_description":"","notes":[{"author":"ratliff","note":"same fix as for CVE-2017-6832, CVE-2017-6833, and CVE-2017-6835"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-multiple-ubsan-crashes/","http://www.openwall.com/lists/oss-security/2017/03/13/9","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6837"],"bugs":["https://github.com/mpruett/audiofile/issues/41","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/antlarr/audiofile/commit/c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6836","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nHeap-based buffer overflow in the Expand3To4Module::run function in\nlibaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile)\n0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to\ncause a denial of service (crash) via a crafted file.","ubuntu_description":"","notes":[{"author":"ratliff","note":"same fix as for CVE-2017-6830 and CVE-2017-6834"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-expand3to4modulerun-simplemodule-h","http://www.openwall.com/lists/oss-security/2017/03/13/8","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6836"],"bugs":["https://github.com/mpruett/audiofile/issues/40","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c","upstream: https://github.com/antlarr/audiofile/commit/ce536d707b8e2a26baca77320398c45238224ca7"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6835","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nThe reset1 function in libaudiofile/modules/BlockCodec.cpp in Audio File\nLibrary (aka audiofile) 0.3.6 allows remote attackers to cause a denial of\nservice (divide-by-zero error and crash) via a crafted file.","ubuntu_description":"","notes":[{"author":"ratliff","note":"same fix as for CVE-2017-6832, CVE-2017-6833, CVE-2017-6835"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-divide-by-zero-in-blockcodecreset1-blockcodec-cpp","http://www.openwall.com/lists/oss-security/2017/03/13/7","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6835"],"bugs":["https://github.com/mpruett/audiofile/issues/39","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6834","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nHeap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in\nAudio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2,\n0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service\n(crash) via a crafted file.","ubuntu_description":"","notes":[{"author":"ratliff","note":"same fix as for CVE-2017-6830 and CVE-2017-6834"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-ulaw2linear_buf-g711-cpp","http://www.openwall.com/lists/oss-security/2017/03/13/6","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6834"],"bugs":["https://github.com/mpruett/audiofile/issues/38","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6833","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nThe runPull function in libaudiofile/modules/BlockCodec.cpp in Audio File\nLibrary (aka audiofile) 0.3.6 allows remote attackers to cause a denial of\nservice (divide-by-zero error and crash) via a crafted file.","ubuntu_description":"","notes":[{"author":"ratliff","note":"same fix as for CVE-2017-6832"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-divide-by-zero-in-blockcodecrunpull-blockcodec-cpp","http://www.openwall.com/lists/oss-security/2017/03/13/5","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6833"],"bugs":["https://github.com/mpruett/audiofile/issues/37","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6832","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nHeap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File\nLibrary (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0,\n0.2.7 allows remote attackers to cause a denial of service (crash) via a\ncrafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-msadpcmdecodeblock-msadpcm-cpp","http://www.openwall.com/lists/oss-security/2017/03/13/4","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6832"],"bugs":["https://github.com/mpruett/audiofile/issues/36","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6831","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nHeap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in\nAudio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2,\n0.3.1, 0.3.0 and 0.2.7 allows remote attackers to cause a denial of service\n(crash) via a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-imadecodeblockwave-ima-cpp","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6831"],"bugs":["https://github.com/mpruett/audiofile/issues/35","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/antlarr/audiofile/commit/a2e9eab8ea87c4ffc494d839ebb4ea145eb9f2e6"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6830","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nHeap-based buffer overflow in the alaw2linear_buf function in G711.cpp in\nAudio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a\ndenial of service (crash) via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"not mentioned in Debian changelog, but is fixed in 0.3.6-4"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-alaw2linear_buf-g711-cpp","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6830"],"bugs":["https://github.com/mpruett/audiofile/issues/34","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c","upstream: https://github.com/antlarr/audiofile/commit/ce536d707b8e2a26baca77320398c45238224ca7"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2016-10169","published":"2017-03-14T00:00:00","updated_at":"2025-08-25T21:52:51.024149+00:00","description":"\nThe read_code function in read_words.c in Wavpack before 5.1.0 allows\nremote attackers to cause a denial of service (out-of-bounds read) via a\ncrafted WV file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/wavpack/mailman/message/35557889/","https://ubuntu.com/security/notices/USN-3568-1","https://www.cve.org/CVERecord?id=CVE-2016-10169"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853076"],"patches":{"wavpack":["upstream: https://github.com/dbry/WavPack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc"]},"tags":{},"packages":[{"name":"wavpack","source":"https://ubuntu.com/security/cve?package=wavpack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wavpack","debian":"https://tracker.debian.org/pkg/wavpack","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.70.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.0-2,5.1.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.75.2-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"5.0.0-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"5.0.0-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3568-1"],"notices":[{"id":"USN-3568-1","title":"WavPack vulnerabilities","summary":"WavPack could be made to crash if it opened a specially crafted\nfile.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-02-12T18:15:33.022373","description":"Hanno Böck discovered that WavPack incorrectly handled certain\nWV files. An attacker could possibly use this to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2016-10169)\n\nJoonun Jang discovered that WavPack incorrectly handled certain\nRF64 files. An attacker could possibly use this to cause a denial\nof service. This issue only affected Ubuntu 17.10. (CVE-2018-6767)\n","is_hidden":false,"release_packages":{"artful":[{"name":"wavpack","version":"5.1.0-2ubuntu0.1","description":"audio codec (lossy and lossless) - encoder and decoder","is_source":true},{"name":"libwavpack1","version":"5.1.0-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu0.1"},{"name":"wavpack","version":"5.1.0-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu0.1"}],"trusty":[{"name":"wavpack","version":"4.70.0-1ubuntu0.1","description":"audio codec (lossy and lossless) - encoder and decoder","is_source":true},{"name":"libwavpack-dev","version":"4.70.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/4.70.0-1ubuntu0.1","pocket":"security"},{"name":"libwavpack1","version":"4.70.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/4.70.0-1ubuntu0.1","pocket":"security"},{"name":"wavpack","version":"4.70.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/4.70.0-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"wavpack","version":"4.75.2-2ubuntu0.1","description":"audio codec (lossy and lossless) - encoder and decoder","is_source":true},{"name":"libwavpack-dev","version":"4.75.2-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/4.75.2-2ubuntu0.1","pocket":"security"},{"name":"libwavpack1","version":"4.75.2-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/4.75.2-2ubuntu0.1","pocket":"security"},{"name":"wavpack","version":"4.75.2-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wavpack","version_link":"https://launchpad.net/ubuntu/+source/wavpack/4.75.2-2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10169","CVE-2018-6767"]}]},{"id":"CVE-2017-6807","published":"2017-03-13T14:59:00","updated_at":"2025-08-25T22:36:30.683262+00:00","description":"\nmod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session\nTransfer attack, where a user with access to one web site running on a\nserver can copy their session cookie to a different web site on the same\nserver to get access to that site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4597-1","https://www.cve.org/CVERecord?id=CVE-2017-6807"],"bugs":[""],"patches":{"libapache2-mod-auth-mellon":["upstream: https://github.com/UNINETT/mod_auth_mellon/commit/7af21c53da7bb1de024274ee6da30bc22316a079"]},"tags":{},"packages":[{"name":"libapache2-mod-auth-mellon","source":"https://ubuntu.com/security/cve?package=libapache2-mod-auth-mellon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache2-mod-auth-mellon","debian":"https://tracker.debian.org/pkg/libapache2-mod-auth-mellon","statuses":[{"release_codename":"xenial","status":"released","description":"0.12.0-2+deb9u1build0.16.04.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"0.13.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.13.1-1build2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.13.1-1build2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.13.1-1build2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.13.1-1build2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.13.1-1build2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.13.1-1build2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.0-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-4597-1"],"notices":[{"id":"USN-4597-1","title":"mod_auth_mellon vulnerabilities","summary":"Several security issues were fixed in mod_auth_mellon.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-10-22T12:47:17.497290","description":"François Kooman discovered that mod_auth_mellon incorrectly handled\ncookies. An attacker could possibly use this issue to cause a Cross-Site\nSession Transfer attack. (CVE-2017-6807)\n\nIt was discovered that mod_auth_mellon incorrectly handled certain requests.\nAn attacker could possibly use this issue to redirect a user to a malicious\nURL. (CVE-2019-3877)\n\nIt was discovered that mod_auth_mellon incorrectly handled certain requests.\nAn attacker could possibly use this issue to access sensitive information.\n(CVE-2019-3878)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libapache2-mod-auth-mellon","version":"0.12.0-2+deb9u1build0.16.04.1","description":"SAML 2.0 authentication module for Apache","is_source":true},{"name":"libapache2-mod-auth-mellon","version":"0.12.0-2+deb9u1build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libapache2-mod-auth-mellon","version_link":"https://launchpad.net/ubuntu/+source/libapache2-mod-auth-mellon/0.12.0-2+deb9u1build0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-3877","CVE-2019-3878","CVE-2017-6807"]}]},{"id":"CVE-2017-5929","published":"2017-03-13T06:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nQOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the\nSocketServer and ServerSocketReceiver components.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/qos-ch/logback/commit/f46044b805bca91efe5fd6afe52257cd02f775f8","https://github.com/qos-ch/logback/commit/979b042cb1f0b4c1e5869ccc8912e68c39f769f9","https://github.com/qos-ch/logback/commit/7fbea6127fa98fc48368ca5e8540eefe0e60cec5","https://github.com/qos-ch/logback/commit/3b4f605454534b304770eeee3cb343521fcd6968","https://www.cve.org/CVERecord?id=CVE-2017-5929"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857343"],"patches":{"logback":[]},"tags":{},"packages":[{"name":"logback","source":"https://ubuntu.com/security/cve?package=logback","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=logback","debian":"https://tracker.debian.org/pkg/logback","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.2.3-2ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.1.9-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6829","published":"2017-03-13T00:00:00","updated_at":"2025-08-25T22:36:35.474430+00:00","description":"\nThe decodeSample function in IMA.cpp in Audio File Library (aka audiofile)\n0.3.6 allows remote attackers to cause a denial of service (crash) via a\ncrafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/02/20/audiofile-global-buffer-overflow-in-decodesample-ima-cpp","https://ubuntu.com/security/notices/USN-3241-1","https://www.cve.org/CVERecord?id=CVE-2017-6829"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857651","https://github.com/mpruett/audiofile/issues/33","https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1674005","https://bugzilla.opensuse.org/show_bug.cgi?id=1026981"],"patches":{"audiofile":["upstream: https://github.com/mpruett/audiofile/pull/43/commits/25eb00ce913452c2e614548d7df93070bf0d066f"]},"tags":{},"packages":[{"name":"audiofile","source":"https://ubuntu.com/security/cve?package=audiofile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=audiofile","debian":"https://tracker.debian.org/pkg/audiofile","statuses":[{"release_codename":"precise","status":"released","description":"0.3.3-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.6-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.6-2ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.6-2ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.3.6-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3241-1"],"notices":[{"id":"USN-3241-1","title":"audiofile vulnerabilities","summary":"audiofile could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-22T15:51:48.834649","description":"Agostino Sarubbo discovered that audiofile incorrectly handled certain\nmalformed audio files. If a user or automated system were tricked into\nprocessing a specially crafted audio file, a remote attacker could cause\napplications linked against audiofile to crash, leading to a denial of\nservice, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"audiofile","version":"0.3.3-2ubuntu0.3","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"libaudiofile1","version":"0.3.3-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.3-2ubuntu0.3"}],"trusty":[{"name":"audiofile","version":"0.3.6-2ubuntu0.14.04.2","description":"Open-source version of the SGI audiofile library","is_source":true},{"name":"audiofile-tools","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile-dev","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"},{"name":"libaudiofile1","version":"0.3.6-2ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/audiofile","version_link":"https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-6827","CVE-2017-6828","CVE-2017-6829","CVE-2017-6830","CVE-2017-6831","CVE-2017-6832","CVE-2017-6833","CVE-2017-6834","CVE-2017-6835","CVE-2017-6836","CVE-2017-6837","CVE-2017-6838","CVE-2017-6839"]}]},{"id":"CVE-2017-6820","published":"2017-03-12T05:59:00","updated_at":"2026-03-30T22:07:22.866335+00:00","description":"\nrcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is\nsusceptible to a cross-site scripting vulnerability via a crafted Cascading\nStyle Sheets (CSS) token sequence within an SVG element.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/roundcube/roundcubemail/commit/fa2824fdcd44af3f970b2797feb47652482c8305","https://github.com/roundcube/roundcubemail/commit/cbd35626f7db7855f3b5e2db00d28ecc1554e9f4","https://github.com/roundcube/roundcubemail/wiki/Changelog#release-124","https://github.com/roundcube/roundcubemail/releases/tag/1.1.8","https://github.com/roundcube/roundcubemail/releases/tag/1.2.4","https://roundcube.net/news/2017/03/10/updates-1.2.4-and-1.1.8-released","https://www.cve.org/CVERecord?id=CVE-2017-6820","https://ubuntu.com/security/notices/USN-8132-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857473"],"patches":{"roundcube":[]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.2~beta+dfsg.1-0ubuntu1+esm7","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.3+dfsg.1-3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8132-1"],"notices":[{"id":"USN-8132-1","title":"Roundcube Webmail vulnerabilities","summary":"Several security issues were fixed in Roundcube Webmail.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-30T21:08:01.679731","description":"It was discovered that Roundcube Webmail did not properly sanitize \ncertain HTML elements within the e-mail body. An attacker could possibly \nuse this issue to cause a cross-site scripting attack. This issue was only \naddressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069)\n\nIt was discovered that Roundcube Webmail did not properly handle certain \nconfiguration parameters. An attacker could possibly use this issue to \nexecute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS. \n(CVE-2016-9920)\n\nIt was discovered that Roundcube Webmail did not properly sanitize CSS styles \nwithin SVG documents. An attacker could possibly use this issue to cause \na cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS.\n(CVE-2017-6820)\n\nIt was discovered that Roundcube Webmail did not properly restrict exec call in \ncertain drivers of the password plugin. An authenticated user could possibly \nuse this issue to perform arbitrary password resets. This issue was only addressed in \nUbuntu 16.04 LTS. (CVE-2017-8114)\n\nIt was discovered that Roundcube Webmail did not properly set file permissions within \nthe Enigma plugin. An attacker could possibly use this issue to exfiltrate GPG private \nkeys via network connectivity. (CVE-2018-1000071)\n\nIt was discovered that Roundcube Webmail did not properly handle GnuPG MDC \nintegrity-protection warnings. An attacker could possibly use this issue to obtain \nsensitive information from encrypted communications. (CVE-2018-19205)\n\nIt was discovered that Roundcube Webmail did not properly sanitize and