{"cves":[{"id":"CVE-2016-9401","published":"2017-01-23T00:00:00","updated_at":"2025-08-07T17:17:38.820028+00:00","description":"\npopd in bash might allow local users to bypass the restricted shell and\ncause a use-after-free via a crafted address.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"not sure how this has security impact"}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/17/5","https://ubuntu.com/security/notices/USN-3294-1","https://www.cve.org/CVERecord?id=CVE-2016-9401"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844727"],"patches":{"bash":["upstream: https://ftp.gnu.org/pub/gnu/bash/bash-4.4-patches/bash44-006"]},"tags":{},"packages":[{"name":"bash","source":"https://ubuntu.com/security/cve?package=bash","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bash","debian":"https://tracker.debian.org/pkg/bash","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.3-7ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.3-14ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.3-15ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"4.4-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"4.4-5ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3294-1"],"notices":[{"id":"USN-3294-1","title":"Bash vulnerabilities","summary":"Several security issues were fixed in Bash.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-05-17T17:06:15.319787","description":"Bernd Dietzel discovered that Bash incorrectly expanded the hostname when\ndisplaying the prompt. If a remote attacker were able to modify a hostname,\nthis flaw could be exploited to execute arbitrary code. This issue only\naffected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10.\n(CVE-2016-0634)\n\nIt was discovered that Bash incorrectly handled the SHELLOPTS and PS4\nenvironment variables. A local attacker could use this issue to execute\narbitrary code with root privileges. This issue only affected Ubuntu 14.04\nLTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7543)\n\nIt was discovered that Bash incorrectly handled the popd command. A remote\nattacker could possibly use this issue to bypass restricted shells.\n(CVE-2016-9401)\n\nIt was discovered that Bash incorrectly handled path autocompletion. A\nlocal attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 17.04. (CVE-2017-5932)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"bash","version":"4.3-7ubuntu1.7","description":"GNU Bourne Again SHell","is_source":true},{"name":"bash","version":"4.3-7ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-7ubuntu1.7","pocket":"security"},{"name":"bash-builtins","version":"4.3-7ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-7ubuntu1.7","pocket":"security"},{"name":"bash-doc","version":"4.3-7ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-7ubuntu1.7","pocket":"security"},{"name":"bash-static","version":"4.3-7ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-7ubuntu1.7","pocket":"security"}],"xenial":[{"name":"bash","version":"4.3-14ubuntu1.2","description":"GNU Bourne Again SHell","is_source":true},{"name":"bash","version":"4.3-14ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-14ubuntu1.2","pocket":"security"},{"name":"bash-builtins","version":"4.3-14ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-14ubuntu1.2","pocket":"security"},{"name":"bash-doc","version":"4.3-14ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-14ubuntu1.2","pocket":"security"},{"name":"bash-static","version":"4.3-14ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-14ubuntu1.2","pocket":"security"}],"yakkety":[{"name":"bash","version":"4.3-15ubuntu1.1","description":"GNU Bourne Again SHell","is_source":true},{"name":"bash","version":"4.3-15ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.3-15ubuntu1.1"}],"zesty":[{"name":"bash","version":"4.4-2ubuntu1.1","description":"GNU Bourne Again SHell","is_source":true},{"name":"bash","version":"4.4-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bash","version_link":"https://launchpad.net/ubuntu/+source/bash/4.4-2ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2016-0634","CVE-2016-7543","CVE-2016-9401","CVE-2017-5932"]}]},{"id":"CVE-2016-9381","published":"2017-01-23T00:00:00","updated_at":"2025-08-25T22:13:39.965445+00:00","description":"\nRace condition in QEMU in Xen allows local x86 HVM guest OS administrators\nto gain privileges by changing certain data on shared rings, aka a \"double\nfetch\" vulnerability.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is XSA-197"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-197.html","https://ubuntu.com/security/notices/USN-3261-1","https://www.cve.org/CVERecord?id=CVE-2016-9381"],"bugs":[""],"patches":{"xen":[],"qemu-kvm":[],"qemu":["upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=b85f9dfdb156ae2a2a52f39a36e9f1f270614cd2"]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.33","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.11","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:2.6.1+dfsg-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4.1.6.1-0ubuntu0.12.04.13","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3261-1"],"notices":[{"id":"USN-3261-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2017-04-20T18:33:13.848442","description":"Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU\ndevice. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)\n\nLi Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-10155)\n\nLi Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)\n\nIt was discovered that QEMU incorrectly handled the JAZZ RC4030 device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8667)\n\nIt was discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8669)\n\nIt was discovered that QEMU incorrectly handled the shared rings when used\nwith Xen. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. (CVE-2016-9381)\n\nJann Horn discovered that QEMU incorrectly handled VirtFS directory\nsharing. A privileged attacker inside the guest could use this issue to\naccess files on the host file system outside of the shared directory and\npossibly escalate their privileges. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. (CVE-2016-9602)\n\nGerd Hoffmann discovered that QEMU incorrectly handled the Cirrus VGA\ndevice when being used with a VNC connection. A privileged attacker inside\nthe guest could use this issue to cause QEMU to crash, resulting in a\ndenial of service, or possibly execute arbitrary code on the host. In the\ndefault installation, when QEMU is used with libvirt, attackers would be\nisolated by the libvirt AppArmor profile. (CVE-2016-9603)\n\nIt was discovered that QEMU incorrectly handled the ColdFire Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2016-9776)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to leak\ncontents of host memory. This issue only affected Ubuntu 16.04 LTS and\nUbuntu 16.10. (CVE-2016-9845, CVE-2016-9908)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9846, CVE-2016-9912, CVE-2017-5552,\nCVE-2017-5578, CVE-2017-5857)\n\nLi Qiang discovered that QEMU incorrectly handled the USB redirector. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9907)\n\nLi Qiang discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-9911)\n\nLi Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2016-9913, CVE-2016-9914,\nCVE-2016-9915, CVE-2016-9916)\n\nQinghao Tang, Li Qiang, and Jiangxin discovered that QEMU incorrectly\nhandled the Cirrus VGA device. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2016-9921, CVE-2016-9922)\n\nWjjzhang and Li Qiang discovered that QEMU incorrectly handled the Cirrus\nVGA device. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2615)\n\nIt was discovered that QEMU incorrectly handled the Cirrus VGA device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary code\non the host. In the default installation, when QEMU is used with libvirt,\nattackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2620)\n\nIt was discovered that QEMU incorrectly handled VNC connections. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2017-2633)\n\nLi Qiang discovered that QEMU incorrectly handled the ac97 audio device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5525)\n\nLi Qiang discovered that QEMU incorrectly handled the es1370 audio device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5526)\n\nLi Qiang discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5579)\n\nJiang Xin discovered that QEMU incorrectly handled SDHCI device emulation.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode on the host. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-5667)\n\nLi Qiang discovered that QEMU incorrectly handled the MegaRAID SAS device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5856)\n\nLi Qiang discovered that QEMU incorrectly handled the CCID Card device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5898)\n\nLi Qiang discovered that QEMU incorrectly handled USB xHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2017-5973)\n\nJiang Xin and Wjjzhang discovered that QEMU incorrectly handled SDHCI\ndevice emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2017-5987)\n\nLi Qiang discovered that QEMU incorrectly handled USB OHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to hang, resulting in a denial of service. (CVE-2017-6505)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"}],"yakkety":[{"name":"qemu","version":"1:2.6.1+dfsg-0ubuntu5.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-aarch64","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-arm","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-mips","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-misc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-ppc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-s390x","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-sparc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-x86","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"}]},"type":"USN","cves_ids":["CVE-2016-10028","CVE-2016-10029","CVE-2016-10155","CVE-2016-7907","CVE-2016-8667","CVE-2016-8669","CVE-2016-9381","CVE-2016-9602","CVE-2016-9603","CVE-2016-9776","CVE-2016-9845","CVE-2016-9846","CVE-2016-9907","CVE-2016-9908","CVE-2016-9911","CVE-2016-9912","CVE-2016-9913","CVE-2016-9914","CVE-2016-9915","CVE-2016-9916","CVE-2016-9921","CVE-2016-9922","CVE-2017-2615","CVE-2017-2620","CVE-2017-2633","CVE-2017-5525","CVE-2017-5526","CVE-2017-5552","CVE-2017-5578","CVE-2017-5579","CVE-2017-5667","CVE-2017-5856","CVE-2017-5857","CVE-2017-5898","CVE-2017-5973","CVE-2017-5987","CVE-2017-6505"]}]},{"id":"CVE-2016-6223","published":"2017-01-23T00:00:00","updated_at":"2025-08-25T22:07:33.466876+00:00","description":"\nThe TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in\nlibtiff before 4.0.7 allows remote attackers to cause a denial of service\n(crash) or possibly obtain sensitive information via a negative index in a\nfile-content buffer.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this will not be fixed in precise/esm"}],"codename":null,"priority":"low","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/07/13/3","https://ubuntu.com/security/notices/USN-3212-1","https://www.cve.org/CVERecord?id=CVE-2016-6223"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842270"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/0ba5d8814a17a64bdb8d9035f4c533f3f3f4b496"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.0.6-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3212-1"],"notices":[{"id":"USN-3212-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-27T18:04:10.120804","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"}],"yakkety":[{"name":"tiff","version":"4.0.6-2ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"},{"name":"libtiff5","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-7554","CVE-2015-8668","CVE-2016-10092","CVE-2016-10093","CVE-2016-10094","CVE-2016-3622","CVE-2016-3623","CVE-2016-3624","CVE-2016-3632","CVE-2016-3658","CVE-2016-3945","CVE-2016-3990","CVE-2016-3991","CVE-2016-5314","CVE-2016-5315","CVE-2016-5316","CVE-2016-5317","CVE-2016-5320","CVE-2016-5321","CVE-2016-5322","CVE-2016-5323","CVE-2016-5652","CVE-2016-5875","CVE-2016-6223","CVE-2016-8331","CVE-2016-9273","CVE-2016-9297","CVE-2016-9448","CVE-2016-9453","CVE-2016-9532","CVE-2016-9533","CVE-2016-9534","CVE-2016-9535","CVE-2016-9536","CVE-2016-9537","CVE-2016-9538","CVE-2016-9539","CVE-2016-9540","CVE-2017-5225"]}]},{"id":"CVE-2017-5545","published":"2017-01-21T01:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nThe main function in plistutil.c in libimobiledevice libplist through 1.12\nallows attackers to obtain sensitive information from process memory or\ncause a denial of service (buffer over-read) via Apple Property List data\nthat is too short.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Affected utility is found in the libplist source package rather than\nin the libimobiledevice source package"},{"author":"sbeattie","note":"also, the affected code is just in the plistutil binary, not\nin the library itself"}],"codename":null,"priority":"negligible","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-5545"],"bugs":["https://github.com/libimobiledevice/libplist/issues/87","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852385"],"patches":{"libplist":["upstream: https://github.com/libimobiledevice/libplist/commit/7391a506352c009fe044dead7baad9e22dd279ee"]},"tags":{"libplist":["universe-binary"]},"packages":[{"name":"libplist","source":"https://ubuntu.com/security/cve?package=libplist","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libplist","debian":"https://tracker.debian.org/pkg/libplist","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12+git+1+e37ca00-0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.12+git+1+e37ca00-0.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5319","published":"2017-01-20T15:59:00","updated_at":"2025-08-25T22:06:18.398724+00:00","description":"\nHeap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier\nallows remote attackers to crash the application via a crafted bmp file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream removed the bmp2tiff utility in 4.0.7\ncan't reproduce on trusty and xenial, marking as not-affected"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2016/q2/486","https://www.cve.org/CVERecord?id=CVE-2016-5319"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842046","http://bugzilla.maptools.org/show_bug.cgi?id=2562"],"patches":{"tiff":[]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.0.3-7ubuntu0.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.6-3","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.0.6-1ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-2578","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:59:41.209883+00:00","description":"\nIn Moodle 3.x, there is XSS in the assignment submission page.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=345915","https://www.cve.org/CVERecord?id=CVE-2017-2578"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.18+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-2576","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:59:41.209883+00:00","description":"\nIn Moodle 2.x and 3.x, there is incorrect sanitization of attributes in\nforums.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=345912","https://www.cve.org/CVERecord?id=CVE-2017-2576"],"bugs":[""],"patches":{"moodle":["upstream: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-56225"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.18+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-8644","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:56:14.060909+00:00","description":"\nIn Moodle 2.x and 3.x, the capability to view course notes is checked in\nthe wrong context.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://tracker.moodle.org/browse/MDL-51347","https://www.cve.org/CVERecord?id=CVE-2016-8644"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.17+dfsg-1, 3.1.3, 3.0.7, 2.9.9 and 2.7.17","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-8643","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:56:14.060909+00:00","description":"\nIn Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins\nvia web services.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://tracker.moodle.org/browse/MDL-56065","https://www.cve.org/CVERecord?id=CVE-2016-8643"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.17+dfsg-1, 3.1.3, 3.0.7, 2.9.9 and 2.7.17","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-8642","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:56:14.060909+00:00","description":"\nIn Moodle 2.x and 3.x, the question engine allows access to files that\nshould not be available.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://tracker.moodle.org/browse/MDL-53744","https://www.cve.org/CVERecord?id=CVE-2016-8642"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.17+dfsg-1, 3.1.3, 3.0.7, 2.9.9 and 2.7.17","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-7038","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:55:59.284477+00:00","description":"\nIn Moodle 2.x and 3.x, web service tokens are not invalidated when the user\npassword is changed or forced to be changed.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=339631","https://www.cve.org/CVERecord?id=CVE-2016-7038"],"bugs":[""],"patches":{"moodle":["upstream: https://git.moodle.org/gw?p=moodle.git;a=commit;h=753504fbe0a32dd05cf40e1fa33382473db65279"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.16+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5014","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:55:13.683398+00:00","description":"\nIn Moodle 2.x and 3.x, an unenrolled user still receives event monitor\nnotifications even though they can no longer access the course.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=336699","https://www.cve.org/CVERecord?id=CVE-2016-5014"],"bugs":[""],"patches":{"moodle":["upstream: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53431"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5013","published":"2017-01-20T08:59:00","updated_at":"2025-08-26T11:55:13.683398+00:00","description":"\nIn Moodle 2.x and 3.x, text injection can occur in email headers,\npotentially leading to outbound spam.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/search.php?id=1&search=CVE-2016-5013","https://www.cve.org/CVERecord?id=CVE-2016-5013"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.15+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5012","published":"2017-01-20T08:59:00","updated_at":"2025-08-25T22:04:37.923819+00:00","description":"\nIn Moodle 3.x, glossary search displays entries without checking user\npermissions to view them.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=336697","https://www.cve.org/CVERecord?id=CVE-2016-5012"],"bugs":[""],"patches":{"moodle":["upstream: https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-54844"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9436","published":"2017-01-20T00:00:00","updated_at":"2025-08-25T22:13:54.015727+00:00","description":"\nparsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize\nvalues, which allows remote attackers to crash the application via a\ncrafted html file, related to a tag.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commit fix as for CVE-2016-9435"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/tats/w3m/issues/16","http://www.openwall.com/lists/oss-security/2016/11/18/3","https://ubuntu.com/security/notices/USN-3214-1","https://www.cve.org/CVERecord?id=CVE-2016-9436"],"bugs":[""],"patches":{"w3m":["debian: https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd"]},"tags":{},"packages":[{"name":"w3m","source":"https://ubuntu.com/security/cve?package=w3m","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=w3m","debian":"https://tracker.debian.org/pkg/w3m","statuses":[{"release_codename":"precise","status":"released","description":"0.5.3-5ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.5.3-15ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.5.3-30","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.5.3-26ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.5.3-32","component":null,"pocket":"security"}]}],"notices_ids":["USN-3214-1"],"notices":[{"id":"USN-3214-1","title":"w3m vulnerabilities","summary":"Several security issues were fixed in w3m.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-02T14:48:47.105216","description":"A large number of security issues were discovered in the w3m browser. If a\nuser were tricked into viewing a malicious website, a remote attacker could\nexploit a variety of issues related to web browser security, including\ncross-site scripting attacks, denial of service attacks, and arbitrary code\nexecution.\n","is_hidden":false,"release_packages":{"precise":[{"name":"w3m","version":"0.5.3-5ubuntu1.2","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m","version":"0.5.3-5ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-5ubuntu1.2"}],"trusty":[{"name":"w3m","version":"0.5.3-15ubuntu0.1","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m","version":"0.5.3-15ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-15ubuntu0.1","pocket":"security"},{"name":"w3m-img","version":"0.5.3-15ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-15ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-9422","CVE-2016-9423","CVE-2016-9424","CVE-2016-9425","CVE-2016-9426","CVE-2016-9428","CVE-2016-9429","CVE-2016-9430","CVE-2016-9431","CVE-2016-9432","CVE-2016-9433","CVE-2016-9434","CVE-2016-9435","CVE-2016-9436","CVE-2016-9437","CVE-2016-9438","CVE-2016-9439","CVE-2016-9440","CVE-2016-9441","CVE-2016-9442","CVE-2016-9443","CVE-2016-9622","CVE-2016-9623","CVE-2016-9624","CVE-2016-9625","CVE-2016-9626","CVE-2016-9627","CVE-2016-9628","CVE-2016-9629","CVE-2016-9630","CVE-2016-9631","CVE-2016-9632","CVE-2016-9633"]}]},{"id":"CVE-2016-9435","published":"2017-01-20T00:00:00","updated_at":"2025-08-25T22:13:54.015727+00:00","description":"\nThe HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does\nnot properly initialize values, which allows remote attackers to crash the\napplication via a crafted html file, related to
tags.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/tats/w3m/issues/16","http://www.openwall.com/lists/oss-security/2016/11/18/3","https://ubuntu.com/security/notices/USN-3214-1","https://www.cve.org/CVERecord?id=CVE-2016-9435"],"bugs":[""],"patches":{"w3m":["debian: https://github.com/tats/w3m/commit/33509cc81ec5f2ba44eb6fd98bd5c1b5873e46bd"]},"tags":{},"packages":[{"name":"w3m","source":"https://ubuntu.com/security/cve?package=w3m","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=w3m","debian":"https://tracker.debian.org/pkg/w3m","statuses":[{"release_codename":"upstream","status":"released","description":"0.5.3-30","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.5.3-26ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.5.3-32","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.5.3-5ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.5.3-15ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3214-1"],"notices":[{"id":"USN-3214-1","title":"w3m vulnerabilities","summary":"Several security issues were fixed in w3m.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-02T14:48:47.105216","description":"A large number of security issues were discovered in the w3m browser. If a\nuser were tricked into viewing a malicious website, a remote attacker could\nexploit a variety of issues related to web browser security, including\ncross-site scripting attacks, denial of service attacks, and arbitrary code\nexecution.\n","is_hidden":false,"release_packages":{"precise":[{"name":"w3m","version":"0.5.3-5ubuntu1.2","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m","version":"0.5.3-5ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-5ubuntu1.2"}],"trusty":[{"name":"w3m","version":"0.5.3-15ubuntu0.1","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m","version":"0.5.3-15ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-15ubuntu0.1","pocket":"security"},{"name":"w3m-img","version":"0.5.3-15ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-15ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-9422","CVE-2016-9423","CVE-2016-9424","CVE-2016-9425","CVE-2016-9426","CVE-2016-9428","CVE-2016-9429","CVE-2016-9430","CVE-2016-9431","CVE-2016-9432","CVE-2016-9433","CVE-2016-9434","CVE-2016-9435","CVE-2016-9436","CVE-2016-9437","CVE-2016-9438","CVE-2016-9439","CVE-2016-9440","CVE-2016-9441","CVE-2016-9442","CVE-2016-9443","CVE-2016-9622","CVE-2016-9623","CVE-2016-9624","CVE-2016-9625","CVE-2016-9626","CVE-2016-9627","CVE-2016-9628","CVE-2016-9629","CVE-2016-9630","CVE-2016-9631","CVE-2016-9632","CVE-2016-9633"]}]},{"id":"CVE-2016-5323","published":"2017-01-20T00:00:00","updated_at":"2025-08-25T22:06:23.625607+00:00","description":"\nThe _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote\nattackers to cause a denial of service (divide-by-zero error and\napplication crash) via a crafted Tiff image.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"possibly same fix as CVE-2016-5321\nthis will not be fixed in precise/esm"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2016/q2/548","https://ubuntu.com/security/notices/USN-3212-1","https://www.cve.org/CVERecord?id=CVE-2016-5323"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2559"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/d9783e4a1476b6787a51c5ae9e9b3156527589f0","upstream: https://github.com/vadz/libtiff/commit/2f79856097f423eb33796a15fcf700d2ea41bf31"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.0.6-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3212-1"],"notices":[{"id":"USN-3212-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-27T18:04:10.120804","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"}],"yakkety":[{"name":"tiff","version":"4.0.6-2ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"},{"name":"libtiff5","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-7554","CVE-2015-8668","CVE-2016-10092","CVE-2016-10093","CVE-2016-10094","CVE-2016-3622","CVE-2016-3623","CVE-2016-3624","CVE-2016-3632","CVE-2016-3658","CVE-2016-3945","CVE-2016-3990","CVE-2016-3991","CVE-2016-5314","CVE-2016-5315","CVE-2016-5316","CVE-2016-5317","CVE-2016-5320","CVE-2016-5321","CVE-2016-5322","CVE-2016-5323","CVE-2016-5652","CVE-2016-5875","CVE-2016-6223","CVE-2016-8331","CVE-2016-9273","CVE-2016-9297","CVE-2016-9448","CVE-2016-9453","CVE-2016-9532","CVE-2016-9533","CVE-2016-9534","CVE-2016-9535","CVE-2016-9536","CVE-2016-9537","CVE-2016-9538","CVE-2016-9539","CVE-2016-9540","CVE-2017-5225"]}]},{"id":"CVE-2016-5321","published":"2017-01-20T00:00:00","updated_at":"2025-08-25T22:06:18.398724+00:00","description":"\nThe DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers\nto cause a denial of service (invalid read and crash) via a crafted tiff\nimage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2016/q2/549","https://ubuntu.com/security/notices/USN-3212-1","https://ubuntu.com/security/notices/USN-3212-3","https://www.cve.org/CVERecord?id=CVE-2016-5321"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2558"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/d9783e4a1476b6787a51c5ae9e9b3156527589f0","upstream: https://github.com/vadz/libtiff/commit/2f79856097f423eb33796a15fcf700d2ea41bf31"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.0.6-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3212-3","USN-3212-1"],"notices":[{"id":"USN-3212-3","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-19T16:53:41.392151","description":"USN-3212-1 and USN-3212-2 fixed a vulnerabilitiy in LibTIFF. This update provides a subset of\ncorresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that LibTIFF incorrectly handled certain malformed\n images. If a user or automated system were tricked into opening a specially\n crafted image, a remote attacker could crash the application, leading to a\n denial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"precise":[{"name":"tiff","version":"3.9.5-2ubuntu1.10","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff4","version":"3.9.5-2ubuntu1.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.10"},{"name":"libtiff-tools","version":"3.9.5-2ubuntu1.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.10"}]},"type":"USN","cves_ids":["CVE-2015-7554","CVE-2015-8668","CVE-2016-10092","CVE-2016-3623","CVE-2016-3624","CVE-2016-3632","CVE-2016-3990","CVE-2016-3991","CVE-2016-5321","CVE-2016-5322","CVE-2016-8331","CVE-2016-9453","CVE-2016-9533","CVE-2016-9534","CVE-2016-9536","CVE-2016-9537"]},{"id":"USN-3212-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-27T18:04:10.120804","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"}],"yakkety":[{"name":"tiff","version":"4.0.6-2ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"},{"name":"libtiff5","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-7554","CVE-2015-8668","CVE-2016-10092","CVE-2016-10093","CVE-2016-10094","CVE-2016-3622","CVE-2016-3623","CVE-2016-3624","CVE-2016-3632","CVE-2016-3658","CVE-2016-3945","CVE-2016-3990","CVE-2016-3991","CVE-2016-5314","CVE-2016-5315","CVE-2016-5316","CVE-2016-5317","CVE-2016-5320","CVE-2016-5321","CVE-2016-5322","CVE-2016-5323","CVE-2016-5652","CVE-2016-5875","CVE-2016-6223","CVE-2016-8331","CVE-2016-9273","CVE-2016-9297","CVE-2016-9448","CVE-2016-9453","CVE-2016-9532","CVE-2016-9533","CVE-2016-9534","CVE-2016-9535","CVE-2016-9536","CVE-2016-9537","CVE-2016-9538","CVE-2016-9539","CVE-2016-9540","CVE-2017-5225"]}]},{"id":"CVE-2016-5318","published":"2017-01-20T00:00:00","updated_at":"2025-08-25T22:06:18.398724+00:00","description":"\nStack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6\nand earlier allows remote attackers to crash the application via a crafted\ntiff.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same problem as CVE-2015-7554\nwe will not be fixing this issue in precise/esm"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3606-1","https://www.cve.org/CVERecord?id=CVE-2016-5318"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842043","http://bugzilla.maptools.org/show_bug.cgi?id=2561"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/4d4fa0b68ae9ae038959ee4f69ebe288ec892f06"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.6-3","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.0.8-5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.9","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3606-1"],"notices":[{"id":"USN-3606-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-26T11:50:26.215438","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"artful":[{"name":"tiff","version":"4.0.8-5ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.8-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.8-5ubuntu0.1"},{"name":"libtiff5","version":"4.0.8-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.8-5ubuntu0.1"}],"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.9","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.4","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-3186","CVE-2016-5102","CVE-2016-5318","CVE-2017-11613","CVE-2017-12944","CVE-2017-17095","CVE-2017-18013","CVE-2017-5563","CVE-2017-9117","CVE-2017-9147","CVE-2017-9935","CVE-2018-5784"]}]},{"id":"CVE-2016-5317","published":"2017-01-20T00:00:00","updated_at":"2025-08-25T22:06:18.398724+00:00","description":"\nBuffer overflow in the PixarLogDecode function in libtiff.so in the\nPixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME\nnautilus, allows attackers to cause a denial of service attack (crash) via\na crafted TIFF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"possible dupe and same patch as CVE-2016-5314\nthis will not be fixed in precise/esm"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2016/q2/547","https://ubuntu.com/security/notices/USN-3212-1","https://www.cve.org/CVERecord?id=CVE-2016-5317"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=830700","http://bugzilla.maptools.org/show_bug.cgi?id=2557"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/391e77fcd217e78b2c51342ac3ddb7100ecacdd2"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"upstream","status":"released","description":"4.0.7","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.0.6-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3212-1"],"notices":[{"id":"USN-3212-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-27T18:04:10.120804","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"}],"yakkety":[{"name":"tiff","version":"4.0.6-2ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"},{"name":"libtiff5","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-7554","CVE-2015-8668","CVE-2016-10092","CVE-2016-10093","CVE-2016-10094","CVE-2016-3622","CVE-2016-3623","CVE-2016-3624","CVE-2016-3632","CVE-2016-3658","CVE-2016-3945","CVE-2016-3990","CVE-2016-3991","CVE-2016-5314","CVE-2016-5315","CVE-2016-5316","CVE-2016-5317","CVE-2016-5320","CVE-2016-5321","CVE-2016-5322","CVE-2016-5323","CVE-2016-5652","CVE-2016-5875","CVE-2016-6223","CVE-2016-8331","CVE-2016-9273","CVE-2016-9297","CVE-2016-9448","CVE-2016-9453","CVE-2016-9532","CVE-2016-9533","CVE-2016-9534","CVE-2016-9535","CVE-2016-9536","CVE-2016-9537","CVE-2016-9538","CVE-2016-9539","CVE-2016-9540","CVE-2017-5225"]}]}],"offset":58740,"limit":20,"total_results":79316}