{"cves":[{"id":"CVE-2017-3231","published":"2017-01-18T00:00:00","updated_at":"2025-08-25T22:32:04.140595+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: Networking). Supported versions that are affected are Java\nSE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable\nvulnerability allows unauthenticated attacker with network access via\nmultiple protocols to compromise Java SE, Java SE Embedded. Successful\nattacks require human interaction from a person other than the attacker.\nSuccessful attacks of this vulnerability can result in unauthorized read\naccess to a subset of Java SE, Java SE Embedded accessible data. Note: This\nvulnerability applies to Java deployments, typically in clients running\nsandboxed Java Web Start applications or sandboxed Java applets, that load\nand run untrusted code (e.g., code that comes from the internet) and rely\non the Java sandbox for security. This vulnerability does not apply to Java\ndeployments, typically in servers, that load and run only trusted code\n(e.g., code installed by an administrator). CVSS v3.0 Base Score 4.3\n(Confidentiality impacts).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/3432537.xml","http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA","http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/dfa1648415a4","https://ubuntu.com/security/notices/USN-3179-1","https://ubuntu.com/security/notices/USN-3194-1","https://ubuntu.com/security/notices/USN-3198-1","https://www.cve.org/CVERecord?id=CVE-2017-3231"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-8":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"precise","status":"released","description":"6b41-1.13.13-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6b41-1.13.13-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u121-2.6.8-1ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u121-2.6.8-1ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u121-b13-0ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8u121-b13-0ubuntu1.16.10.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3198-1","USN-3179-1","USN-3194-1"],"notices":[{"id":"USN-3198-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-02-16T02:22:53.596811","description":"Karthik Bhargavan and Gaetan Leurent discovered that the DES and\nTriple DES ciphers were vulnerable to birthday attacks. A remote\nattacker could possibly use this flaw to obtain clear text data from\nlong encrypted sessions. This update moves those algorithms to the\nlegacy algorithm set and causes them to be used only if no non-legacy\nalgorithms can be negotiated. (CVE-2016-2183)\n\nIt was discovered that OpenJDK accepted ECSDA signatures using\nnon-canonical DER encoding. An attacker could use this to modify or\nexpose sensitive data. (CVE-2016-5546)\n\nIt was discovered that covert timing channel vulnerabilities existed\nin the DSA implementations in OpenJDK. A remote attacker could use\nthis to expose sensitive information. (CVE-2016-5548)\n\nIt was discovered that the URLStreamHandler class in OpenJDK did not\nproperly parse user information from a URL. A remote attacker could\nuse this to expose sensitive information. (CVE-2016-5552)\n\nIt was discovered that the URLClassLoader class in OpenJDK did not\nproperly check access control context when downloading class files. A\nremote attacker could use this to expose sensitive information.\n(CVE-2017-3231)\n\nIt was discovered that the Remote Method Invocation (RMI)\nimplementation in OpenJDK performed deserialization of untrusted\ninputs. A remote attacker could use this to execute arbitrary\ncode. (CVE-2017-3241)\n\nIt was discovered that the Java Authentication and Authorization\nService (JAAS) component of OpenJDK did not properly perform user\nsearch LDAP queries. An attacker could use a specially constructed\nLDAP entry to expose or modify sensitive information. (CVE-2017-3252)\n\nIt was discovered that the PNGImageReader class in OpenJDK did not\nproperly handle iTXt and zTXt chunks. An attacker could use this to\ncause a denial of service (memory consumption). (CVE-2017-3253)\n\nIt was discovered that integer overflows existed in the\nSocketInputStream and SocketOutputStream classes of OpenJDK. An\nattacker could use this to expose sensitive information.\n(CVE-2017-3261)\n\nIt was discovered that the atomic field updaters in the\njava.util.concurrent.atomic package in OpenJDK did not properly\nrestrict access to protected field members. An attacker could use\nthis to specially craft a Java application or applet that could bypass\nJava sandbox restrictions. (CVE-2017-3272)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b41-1.13.13-0ubuntu0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b41-1.13.13-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b41-1.13.13-0ubuntu0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b41-1.13.13-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b41-1.13.13-0ubuntu0.12.04.1"},{"name":"openjdk-6-jdk","version":"6b41-1.13.13-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b41-1.13.13-0ubuntu0.12.04.1"},{"name":"openjdk-6-jre","version":"6b41-1.13.13-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b41-1.13.13-0ubuntu0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b41-1.13.13-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b41-1.13.13-0ubuntu0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b41-1.13.13-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b41-1.13.13-0ubuntu0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b41-1.13.13-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b41-1.13.13-0ubuntu0.12.04.1"}]},"type":"USN","cves_ids":["CVE-2016-2183","CVE-2016-5546","CVE-2016-5548","CVE-2016-5552","CVE-2017-3231","CVE-2017-3241","CVE-2017-3252","CVE-2017-3253","CVE-2017-3261","CVE-2017-3272"]},{"id":"USN-3179-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-01-25T21:05:13.122272","description":"Karthik Bhargavan and Gaetan Leurent discovered that the DES and\nTriple DES ciphers were vulnerable to birthday attacks. A remote\nattacker could possibly use this flaw to obtain clear text data from\nlong encrypted sessions. This update moves those algorithms to the\nlegacy algorithm set and causes them to be used only if no non-legacy\nalgorithms can be negotiated. (CVE-2016-2183)\n\nIt was discovered that OpenJDK accepted ECSDA signatures using\nnon-canonical DER encoding. An attacker could use this to modify or\nexpose sensitive data. (CVE-2016-5546)\n\nIt was discovered that OpenJDK did not properly verify object\nidentifier (OID) length when reading Distinguished Encoding Rules\n(DER) records, as used in x.509 certificates and elsewhere. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2016-5547)\n\nIt was discovered that covert timing channel vulnerabilities existed\nin the DSA and ECDSA implementations in OpenJDK. A remote attacker\ncould use this to expose sensitive information. (CVE-2016-5548,\nCVE-2016-5549)\n\nIt was discovered that the URLStreamHandler class in OpenJDK did not\nproperly parse user information from a URL. A remote attacker could\nuse this to expose sensitive information. (CVE-2016-5552)\n\nIt was discovered that the URLClassLoader class in OpenJDK did not\nproperly check access control context when downloading class files. A\nremote attacker could use this to expose sensitive information.\n(CVE-2017-3231)\n\nIt was discovered that the Remote Method Invocation (RMI)\nimplementation in OpenJDK performed deserialization of untrusted\ninputs. A remote attacker could use this to execute arbitrary\ncode. (CVE-2017-3241)\n\nIt was discovered that the Java Authentication and Authorization\nService (JAAS) component of OpenJDK did not properly perform user\nsearch LDAP queries. An attacker could use a specially constructed\nLDAP entry to expose or modify sensitive information. (CVE-2017-3252)\n\nIt was discovered that the PNGImageReader class in OpenJDK did not\nproperly handle iTXt and zTXt chunks. An attacker could use this to\ncause a denial of service (memory consumption). (CVE-2017-3253)\n\nIt was discovered that integer overflows existed in the\nSocketInputStream and SocketOutputStream classes of OpenJDK. An\nattacker could use this to expose sensitive information.\n(CVE-2017-3261)\n\nIt was discovered that the atomic field updaters in the\njava.util.concurrent.atomic package in OpenJDK did not properly\nrestrict access to protected field members. An attacker could use\nthis to specially craft a Java application or applet that could bypass\nJava sandbox restrictions. (CVE-2017-3272)\n\nIt was discovered that a vulnerability existed in the class\nconstruction implementation in OpenJDK. An attacker could use this\nto specially craft a Java application or applet that could bypass\nJava sandbox restrictions. (CVE-2017-3289)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u121-b13-0ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u121-b13-0ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.04.2","pocket":"security"}],"yakkety":[{"name":"openjdk-8","version":"8u121-b13-0ubuntu1.16.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u121-b13-0ubuntu1.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u121-b13-0ubuntu1.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.10.2"},{"name":"openjdk-8-jre","version":"8u121-b13-0ubuntu1.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.10.2"},{"name":"openjdk-8-jre-headless","version":"8u121-b13-0ubuntu1.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.10.2"},{"name":"openjdk-8-jre-jamvm","version":"8u121-b13-0ubuntu1.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.10.2"},{"name":"openjdk-8-jre-zero","version":"8u121-b13-0ubuntu1.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u121-b13-0ubuntu1.16.10.2"}]},"type":"USN","cves_ids":["CVE-2016-2183","CVE-2016-5546","CVE-2016-5547","CVE-2016-5548","CVE-2016-5549","CVE-2016-5552","CVE-2017-3231","CVE-2017-3241","CVE-2017-3252","CVE-2017-3253","CVE-2017-3261","CVE-2017-3272","CVE-2017-3289"]},{"id":"USN-3194-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-02-09T05:44:32.227903","description":"Karthik Bhargavan and Gaetan Leurent discovered that the DES and\nTriple DES ciphers were vulnerable to birthday attacks. A remote\nattacker could possibly use this flaw to obtain clear text data from\nlong encrypted sessions. This update moves those algorithms to the\nlegacy algorithm set and causes them to be used only if no non-legacy\nalgorithms can be negotiated. (CVE-2016-2183)\n\nIt was discovered that OpenJDK accepted ECSDA signatures using\nnon-canonical DER encoding. An attacker could use this to modify or\nexpose sensitive data. (CVE-2016-5546)\n\nIt was discovered that OpenJDK did not properly verify object\nidentifier (OID) length when reading Distinguished Encoding Rules\n(DER) records, as used in x.509 certificates and elsewhere. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2016-5547)\n\nIt was discovered that covert timing channel vulnerabilities existed\nin the DSA implementations in OpenJDK. A remote attacker could use\nthis to expose sensitive information. (CVE-2016-5548)\n\nIt was discovered that the URLStreamHandler class in OpenJDK did not\nproperly parse user information from a URL. A remote attacker could\nuse this to expose sensitive information. (CVE-2016-5552)\n\nIt was discovered that the URLClassLoader class in OpenJDK did not\nproperly check access control context when downloading class files. A\nremote attacker could use this to expose sensitive information.\n(CVE-2017-3231)\n\nIt was discovered that the Remote Method Invocation (RMI)\nimplementation in OpenJDK performed deserialization of untrusted\ninputs. A remote attacker could use this to execute arbitrary\ncode. (CVE-2017-3241)\n\nIt was discovered that the Java Authentication and Authorization\nService (JAAS) component of OpenJDK did not properly perform user\nsearch LDAP queries. An attacker could use a specially constructed\nLDAP entry to expose or modify sensitive information. (CVE-2017-3252)\n\nIt was discovered that the PNGImageReader class in OpenJDK did not\nproperly handle iTXt and zTXt chunks. An attacker could use this to\ncause a denial of service (memory consumption). (CVE-2017-3253)\n\nIt was discovered that integer overflows existed in the\nSocketInputStream and SocketOutputStream classes of OpenJDK. An\nattacker could use this to expose sensitive information.\n(CVE-2017-3261)\n\nIt was discovered that the atomic field updaters in the\njava.util.concurrent.atomic package in OpenJDK did not properly\nrestrict access to protected field members. An attacker could use\nthis to specially craft a Java application or applet that could bypass\nJava sandbox restrictions. (CVE-2017-3272)\n\nIt was discovered that a vulnerability existed in the class\nconstruction implementation in OpenJDK. An attacker could use this\nto specially craft a Java application or applet that could bypass\nJava sandbox restrictions. (CVE-2017-3289)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u121-2.6.8-1ubuntu0.14.04.3","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-demo","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-doc","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-jre","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"},{"name":"openjdk-7-source","version":"7u121-2.6.8-1ubuntu0.14.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u121-2.6.8-1ubuntu0.14.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-2183","CVE-2016-5546","CVE-2016-5547","CVE-2016-5548","CVE-2016-5552","CVE-2017-3231","CVE-2017-3241","CVE-2017-3252","CVE-2017-3253","CVE-2017-3261","CVE-2017-3272","CVE-2017-3289"]}]},{"id":"CVE-2016-9297","published":"2017-01-18T00:00:00","updated_at":"2025-08-25T22:13:30.167109+00:00","description":"\nThe TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to\ncause a denial of service (out-of-bounds read) via crafted\nTIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"poc in in maptools.org bug entry"},{"author":"tyhicks","note":"The fix for this issue introduced a regression that has been assigned\nCVE-2016-9448"},{"author":"mdeslaur","note":"this will not be fixed in precise/esm"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/12/2","https://ubuntu.com/security/notices/USN-3212-1","https://www.cve.org/CVERecord?id=CVE-2016-9297"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844226","http://bugzilla.maptools.org/show_bug.cgi?id=2590"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/30c9234c7fd0dd5e8b1e83ad44370c875a0270ed"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"upstream","status":"released","description":"4.0.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.0.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-3212-1"],"notices":[{"id":"USN-3212-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-27T18:04:10.120804","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"}],"yakkety":[{"name":"tiff","version":"4.0.6-2ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"},{"name":"libtiff5","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-7554","CVE-2015-8668","CVE-2016-10092","CVE-2016-10093","CVE-2016-10094","CVE-2016-3622","CVE-2016-3623","CVE-2016-3624","CVE-2016-3632","CVE-2016-3658","CVE-2016-3945","CVE-2016-3990","CVE-2016-3991","CVE-2016-5314","CVE-2016-5315","CVE-2016-5316","CVE-2016-5317","CVE-2016-5320","CVE-2016-5321","CVE-2016-5322","CVE-2016-5323","CVE-2016-5652","CVE-2016-5875","CVE-2016-6223","CVE-2016-8331","CVE-2016-9273","CVE-2016-9297","CVE-2016-9448","CVE-2016-9453","CVE-2016-9532","CVE-2016-9533","CVE-2016-9534","CVE-2016-9535","CVE-2016-9536","CVE-2016-9537","CVE-2016-9538","CVE-2016-9539","CVE-2016-9540","CVE-2017-5225"]}]},{"id":"CVE-2016-9273","published":"2017-01-18T00:00:00","updated_at":"2025-08-25T22:13:25.301428+00:00","description":"\ntiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of\nservice (out-of-bounds read) via a crafted file, related to changing\ntd_nstrips in TIFF_STRIPCHOP mode.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this will not be fixed in precise/esm"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/09/20","https://ubuntu.com/security/notices/USN-3212-1","https://www.cve.org/CVERecord?id=CVE-2016-9273"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844013","http://bugzilla.maptools.org/show_bug.cgi?id=2587"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/d651abc097d91fac57f33b5f9447d0a9183f58e7"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.0.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3212-1"],"notices":[{"id":"USN-3212-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-27T18:04:10.120804","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.6","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.1","pocket":"security"}],"yakkety":[{"name":"tiff","version":"4.0.6-2ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"},{"name":"libtiff5","version":"4.0.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-7554","CVE-2015-8668","CVE-2016-10092","CVE-2016-10093","CVE-2016-10094","CVE-2016-3622","CVE-2016-3623","CVE-2016-3624","CVE-2016-3632","CVE-2016-3658","CVE-2016-3945","CVE-2016-3990","CVE-2016-3991","CVE-2016-5314","CVE-2016-5315","CVE-2016-5316","CVE-2016-5317","CVE-2016-5320","CVE-2016-5321","CVE-2016-5322","CVE-2016-5323","CVE-2016-5652","CVE-2016-5875","CVE-2016-6223","CVE-2016-8331","CVE-2016-9273","CVE-2016-9297","CVE-2016-9448","CVE-2016-9453","CVE-2016-9532","CVE-2016-9533","CVE-2016-9534","CVE-2016-9535","CVE-2016-9536","CVE-2016-9537","CVE-2016-9538","CVE-2016-9539","CVE-2016-9540","CVE-2017-5225"]}]},{"id":"CVE-2016-8327","published":"2017-01-18T00:00:00","updated_at":"2025-08-18T17:05:47.257373+00:00","description":"\nVulnerability in the MySQL Server component of Oracle MySQL (subcomponent:\nServer: Replication). Supported versions that are affected are 5.6.34 and\nearlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows\nhigh privileged attacker with network access via multiple protocols to\ncompromise MySQL Server. Successful attacks of this vulnerability can\nresult in unauthorized ability to cause a hang or frequently repeatable\ncrash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 4.4\n(Availability impacts).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"5.6 and 5.7 only"}],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixMSQL","https://ubuntu.com/security/notices/USN-3174-1","https://www.cve.org/CVERecord?id=CVE-2016-8327"],"bugs":[""],"patches":{"mysql-5.5":[],"mysql-5.6":[],"mysql-5.7":[],"mariadb-5.5":[],"mariadb-10.0":[],"percona-xtradb-cluster-5.5":[],"percona-xtradb-cluster-5.6":[],"percona-server-5.6":[],"mysql-8.0":[]},"tags":{},"packages":[{"name":"percona-xtradb-cluster-5.6","source":"https://ubuntu.com/security/cve?package=percona-xtradb-cluster-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-xtradb-cluster-5.6","debian":"https://tracker.debian.org/pkg/percona-xtradb-cluster-5.6","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"percona-server-5.6","source":"https://ubuntu.com/security/cve?package=percona-server-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-server-5.6","debian":"https://tracker.debian.org/pkg/percona-server-5.6","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"this mysql cve does not affect mariadb","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-5.5","source":"https://ubuntu.com/security/cve?package=mariadb-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-5.5","debian":"https://tracker.debian.org/pkg/mariadb-5.5","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.35","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.7","source":"https://ubuntu.com/security/cve?package=mysql-5.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.7","debian":"https://tracker.debian.org/pkg/mysql-5.7","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7.17","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.7.17-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"5.7.17-0ubuntu0.16.10.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-8.0","source":"https://ubuntu.com/security/cve?package=mysql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-8.0","debian":"https://tracker.debian.org/pkg/mysql-8.0","statuses":[{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"percona-xtradb-cluster-5.5","source":"https://ubuntu.com/security/cve?package=percona-xtradb-cluster-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-xtradb-cluster-5.5","debian":"https://tracker.debian.org/pkg/percona-xtradb-cluster-5.5","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3174-1"],"notices":[{"id":"USN-3174-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-01-19T13:32:24.102979","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.5.54 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\nUbuntu 16.04 LTS and Ubuntu 16.10 have been updated to MySQL 5.7.17.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-54.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html\nhttp://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.54-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.54-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.12.04.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.54-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"mysql-5.7","version":"5.7.17-0ubuntu0.16.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"libmysqlclient20","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-client","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-client-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-client-core-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-common","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-server","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-server-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-server-core-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-source-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-testsuite-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"}],"yakkety":[{"name":"mysql-5.7","version":"5.7.17-0ubuntu0.16.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.7","version":"5.7.17-0ubuntu0.16.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.10.1"}]},"type":"USN","cves_ids":["CVE-2016-8318","CVE-2016-8327","CVE-2017-3238","CVE-2017-3243","CVE-2017-3244","CVE-2017-3251","CVE-2017-3256","CVE-2017-3258","CVE-2017-3265","CVE-2017-3273","CVE-2017-3291","CVE-2017-3312","CVE-2017-3313","CVE-2017-3317","CVE-2017-3318","CVE-2017-3319","CVE-2017-3320"]}]},{"id":"CVE-2016-8318","published":"2017-01-18T00:00:00","updated_at":"2025-08-18T17:05:47.257373+00:00","description":"\nVulnerability in the MySQL Server component of Oracle MySQL (subcomponent:\nServer: Security: Encryption). Supported versions that are affected are\n5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability\nallows low privileged attacker with network access via multiple protocols\nto compromise MySQL Server. Successful attacks require human interaction\nfrom a person other than the attacker and while the vulnerability is in\nMySQL Server, attacks may significantly impact additional products.\nSuccessful attacks of this vulnerability can result in unauthorized ability\nto cause a hang or frequently repeatable crash (complete DOS) of MySQL\nServer. CVSS v3.0 Base Score 6.8 (Availability impacts).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"5.6 and 5.7 only"}],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixMSQL","https://ubuntu.com/security/notices/USN-3174-1","https://www.cve.org/CVERecord?id=CVE-2016-8318"],"bugs":[""],"patches":{"mysql-5.5":[],"mysql-5.6":[],"mysql-5.7":[],"mariadb-5.5":[],"mariadb-10.0":[],"percona-xtradb-cluster-5.5":[],"percona-xtradb-cluster-5.6":[],"percona-server-5.6":[],"mysql-8.0":[]},"tags":{},"packages":[{"name":"percona-xtradb-cluster-5.6","source":"https://ubuntu.com/security/cve?package=percona-xtradb-cluster-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-xtradb-cluster-5.6","debian":"https://tracker.debian.org/pkg/percona-xtradb-cluster-5.6","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"percona-server-5.6","source":"https://ubuntu.com/security/cve?package=percona-server-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-server-5.6","debian":"https://tracker.debian.org/pkg/percona-server-5.6","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"this mysql cve does not affect mariadb","component":null,"pocket":"security"}]},{"name":"mariadb-5.5","source":"https://ubuntu.com/security/cve?package=mariadb-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-5.5","debian":"https://tracker.debian.org/pkg/mariadb-5.5","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.35","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-5.7","source":"https://ubuntu.com/security/cve?package=mysql-5.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.7","debian":"https://tracker.debian.org/pkg/mysql-5.7","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7.17","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.7.17-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"5.7.17-0ubuntu0.16.10.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"5.7.17-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mysql-8.0","source":"https://ubuntu.com/security/cve?package=mysql-8.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-8.0","debian":"https://tracker.debian.org/pkg/mysql-8.0","statuses":[{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"percona-xtradb-cluster-5.5","source":"https://ubuntu.com/security/cve?package=percona-xtradb-cluster-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=percona-xtradb-cluster-5.5","debian":"https://tracker.debian.org/pkg/percona-xtradb-cluster-5.5","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3174-1"],"notices":[{"id":"USN-3174-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-01-19T13:32:24.102979","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.5.54 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\nUbuntu 16.04 LTS and Ubuntu 16.10 have been updated to MySQL 5.7.17.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-54.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html\nhttp://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.54-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.54-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.12.04.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.54-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.54-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"mysql-5.7","version":"5.7.17-0ubuntu0.16.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"libmysqlclient20","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-client","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-client-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-client-core-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-common","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-server","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-server-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-server-core-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-source-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"},{"name":"mysql-testsuite-5.7","version":"5.7.17-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1","pocket":"security"}],"yakkety":[{"name":"mysql-5.7","version":"5.7.17-0ubuntu0.16.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.7","version":"5.7.17-0ubuntu0.16.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.7","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.10.1"}]},"type":"USN","cves_ids":["CVE-2016-8318","CVE-2016-8327","CVE-2017-3238","CVE-2017-3243","CVE-2017-3244","CVE-2017-3251","CVE-2017-3256","CVE-2017-3258","CVE-2017-3265","CVE-2017-3273","CVE-2017-3291","CVE-2017-3312","CVE-2017-3313","CVE-2017-3317","CVE-2017-3318","CVE-2017-3319","CVE-2017-3320"]}]},{"id":"CVE-2016-10147","published":"2017-01-18T00:00:00","updated_at":"2026-07-04T07:39:58.897995+00:00","description":"\ncrypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to\ncause a denial of service (NULL pointer dereference and system crash) by\nusing an AF_ALG socket with an incompatible algorithm, as demonstrated by\nmcryptd(md5).","ubuntu_description":"\nMikulas Patocka discovered that the asynchronous multibuffer cryptographic\ndaemon (mcryptd) in the Linux kernel did not properly handle being invoked\nwith incompatible algorithms. A local attacker could use this to cause a\ndenial of service (system crash).","notes":[{"author":"jdstrand","note":"android kernels (flo, goldfish, grouper, maguro, mako and manta) are\nnot supported on the Ubuntu Touch 14.10 and earlier preview kernels\nlinux-lts-saucy no longer receives official support\nlinux-lts-quantal no longer receives official support"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3189-1","https://ubuntu.com/security/notices/USN-3189-2","https://ubuntu.com/security/notices/USN-3190-1","https://ubuntu.com/security/notices/USN-3190-2","https://www.cve.org/CVERecord?id=CVE-2016-10147"],"bugs":[""],"patches":{"linux":["break-fix: 1e65b81a90df50bf450193065cc9073b706b8dda 48a992727d82cb7db076fa15d372178743b1f4cd"],"linux-ti-omap4":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.10.0-19.21","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-62.83","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.8.0-37.39","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.9.0-11.12","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1003.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1009.9","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-1004.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.8.0-39.42~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.18.0-8.9~18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.8.0-39.42~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1004.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-62.83~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.10.0-1004.6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1005.5","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1042.49","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.8.0-1024.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1024.27","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.4.0-1050.54","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1046.50","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.4.0-1046.50","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1046.50","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3190-1","USN-3189-1","USN-3189-2","USN-3190-2"],"notices":[{"id":"USN-3190-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-02-03T09:48:54.952316","description":"Mikulas Patocka discovered that the asynchronous multibuffer cryptographic\ndaemon (mcryptd) in the Linux kernel did not properly handle being invoked\nwith incompatible algorithms. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-10147)\n\nIt was discovered that a use-after-free existed in the KVM susbsystem of\nthe Linux kernel when creating devices. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2016-10150)\n\nQidan He discovered that the ICMP implementation in the Linux kernel did\nnot properly check the size of an ICMP header. A local attacker with\nCAP_NET_ADMIN could use this to expose sensitive information.\n(CVE-2016-8399)\n\nQian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()\nfunction in the Linux kernel. A local attacker could use to cause a denial\nof service (system crash) or possibly execute arbitrary code with\nadministrative privileges. (CVE-2016-8632)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\ndid not properly restrict the VCPU index when I/O APIC is enabled, An\nattacker in a guest VM could use this to cause a denial of service (system\ncrash) or possibly gain privileges in the host OS. (CVE-2016-9777)\n","is_hidden":false,"release_packages":{"yakkety":[{"name":"linux","version":"4.8.0-37.39","description":"Linux kernel","is_source":true},{"name":"linux-image-4.8.0-37-powerpc64-emb","version":"4.8.0-37.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-powerpc-smp","version":"4.8.0.37.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-powerpc-e500mc","version":"4.8.0.37.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-4.8.0-37-generic","version":"4.8.0-37.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-generic","version":"4.8.0.37.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-4.8.0-37-powerpc-e500mc","version":"4.8.0-37.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-lowlatency","version":"4.8.0.37.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-4.8.0-37-lowlatency","version":"4.8.0-37.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-generic-lpae","version":"4.8.0.37.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-4.8.0-37-powerpc-smp","version":"4.8.0-37.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-4.8.0-37-generic-lpae","version":"4.8.0-37.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"},{"name":"linux-image-powerpc64-emb","version":"4.8.0.37.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.8.0-37.39"}]},"type":"USN","cves_ids":["CVE-2016-10147","CVE-2016-10150","CVE-2016-8399","CVE-2016-8632","CVE-2016-9777"]},{"id":"USN-3189-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-02-03T09:12:18.394887","description":"Mikulas Patocka discovered that the asynchronous multibuffer cryptographic\ndaemon (mcryptd) in the Linux kernel did not properly handle being invoked\nwith incompatible algorithms. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-10147)\n\nQidan He discovered that the ICMP implementation in the Linux kernel did\nnot properly check the size of an ICMP header. A local attacker with\nCAP_NET_ADMIN could use this to expose sensitive information.\n(CVE-2016-8399)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux","version":"4.4.0-62.83","description":"Linux kernel","is_source":true},{"name":"linux-raspi2","version":"4.4.0-1042.49","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-snapdragon","version":"4.4.0-1046.50","description":"Linux kernel for Snapdragon Processors","is_source":true},{"name":"linux-image-4.4.0-1042-raspi2","version":"4.4.0-1042.49","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1042.49","pocket":"security"},{"name":"linux-image-4.4.0-1046-snapdragon","version":"4.4.0-1046.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon","version_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1046.50","pocket":"security"},{"name":"linux-image-4.4.0-62-generic","version":"4.4.0-62.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"},{"name":"linux-image-4.4.0-62-generic-lpae","version":"4.4.0-62.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"},{"name":"linux-image-4.4.0-62-lowlatency","version":"4.4.0-62.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc-e500mc","version":"4.4.0-62.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc-smp","version":"4.4.0-62.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc64-emb","version":"4.4.0-62.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc64-smp","version":"4.4.0-62.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"},{"name":"linux-image-extra-4.4.0-62-generic","version":"4.4.0-62.83","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-62.83","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10147","CVE-2016-8399"]},{"id":"USN-3189-2","title":"Linux kernel (Xenial HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-02-03T09:34:34.676076","description":"USN-3189-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nMikulas Patocka discovered that the asynchronous multibuffer cryptographic\ndaemon (mcryptd) in the Linux kernel did not properly handle being invoked\nwith incompatible algorithms. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-10147)\n\nQidan He discovered that the ICMP implementation in the Linux kernel did\nnot properly check the size of an ICMP header. A local attacker with\nCAP_NET_ADMIN could use this to expose sensitive information.\n(CVE-2016-8399)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-xenial","version":"4.4.0-62.83~14.04.1","description":"Linux hardware enablement kernel from Xenial for Trusty","is_source":true},{"name":"linux-image-4.4.0-62-generic","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-62-generic-lpae","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-62-lowlatency","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc-e500mc","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc-smp","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc64-emb","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-62-powerpc64-smp","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"},{"name":"linux-image-extra-4.4.0-62-generic","version":"4.4.0-62.83~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-62.83~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10147","CVE-2016-8399"]},{"id":"USN-3190-2","title":"Linux kernel (Raspberry Pi 2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-02-10T00:44:16.675050","description":"Mikulas Patocka discovered that the asynchronous multibuffer cryptographic\ndaemon (mcryptd) in the Linux kernel did not properly handle being invoked\nwith incompatible algorithms. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-10147)\n\nIt was discovered that a use-after-free existed in the KVM susbsystem of\nthe Linux kernel when creating devices. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2016-10150)\n\nQidan He discovered that the ICMP implementation in the Linux kernel did\nnot properly check the size of an ICMP header. A local attacker with\nCAP_NET_ADMIN could use this to expose sensitive information.\n(CVE-2016-8399)\n\nQian Zhang discovered a heap-based buffer overflow in the tipc_msg_build()\nfunction in the Linux kernel. A local attacker could use to cause a denial\nof service (system crash) or possible execute arbitrary code with\nadministrative privileges. (CVE-2016-8632)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\ndid not properly restrict the VCPU index when I/O APIC is enabled, An\nattacker in a guest VM could use this to cause a denial of service (system\ncrash) or possibly gain privileges in the host OS. (CVE-2016-9777)\n","is_hidden":false,"release_packages":{"yakkety":[{"name":"linux-raspi2","version":"4.8.0-1024.27","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-image-4.8.0-1024-raspi2","version":"4.8.0-1024.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.8.0-1024.27"},{"name":"linux-image-raspi2","version":"4.8.0.1024.27","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.8.0-1024.27"}]},"type":"USN","cves_ids":["CVE-2016-10147","CVE-2016-10150","CVE-2016-8399","CVE-2016-8632","CVE-2016-9777"]}]},{"id":"CVE-2017-5511","published":"2017-01-17T00:00:00","updated_at":"2025-08-25T22:34:43.623689+00:00","description":"\ncoders/psd.c in ImageMagick allows remote attackers to have unspecified\nimpact by leveraging an improper cast, which triggers a heap-based buffer\noverflow.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0180-Fix-improper-cast-that-could-cause-an-overflow-as-de.patch"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/16/6","https://ubuntu.com/security/notices/USN-3222-1","https://www.cve.org/CVERecord?id=CVE-2017-5511"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/347","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851374"],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3222-1"],"notices":[{"id":"USN-3222-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-08T14:02:00.259584","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"}]},"type":"USN","cves_ids":["CVE-2016-10062","CVE-2016-10144","CVE-2016-10145","CVE-2016-10146","CVE-2016-8707","CVE-2017-5506","CVE-2017-5507","CVE-2017-5508","CVE-2017-5510","CVE-2017-5511"]}]},{"id":"CVE-2017-5510","published":"2017-01-17T00:00:00","updated_at":"2025-08-25T22:34:43.623689+00:00","description":"\ncoders/psd.c in ImageMagick allows remote attackers to have unspecified\nimpact via a crafted PSD file, which triggers an out-of-bounds write.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0181-Fix-memory-corruption-heap-overflow-in-psb-file.patch"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/16/6","https://ubuntu.com/security/notices/USN-3222-1","https://www.cve.org/CVERecord?id=CVE-2017-5510"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/348","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851376"],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3222-1"],"notices":[{"id":"USN-3222-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-08T14:02:00.259584","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"}]},"type":"USN","cves_ids":["CVE-2016-10062","CVE-2016-10144","CVE-2016-10145","CVE-2016-10146","CVE-2016-8707","CVE-2017-5506","CVE-2017-5507","CVE-2017-5508","CVE-2017-5510","CVE-2017-5511"]}]},{"id":"CVE-2017-5508","published":"2017-01-17T00:00:00","updated_at":"2025-08-25T22:34:38.850215+00:00","description":"\nHeap-based buffer overflow in the PushQuantumPixel function in ImageMagick\nbefore 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a\ndenial of service (application crash) via a crafted TIFF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0179-Fix-Heap-Buffer-Overflow-TIFF.patch"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=31161","http://www.openwall.com/lists/oss-security/2017/01/16/6","https://ubuntu.com/security/notices/USN-3222-1","https://www.cve.org/CVERecord?id=CVE-2017-5508"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851381"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/379e21cd32483df6e128147af3bc4ce1f82eb9c4"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3222-1"],"notices":[{"id":"USN-3222-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-08T14:02:00.259584","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"}]},"type":"USN","cves_ids":["CVE-2016-10062","CVE-2016-10144","CVE-2016-10145","CVE-2016-10146","CVE-2016-8707","CVE-2017-5506","CVE-2017-5507","CVE-2017-5508","CVE-2017-5510","CVE-2017-5511"]}]},{"id":"CVE-2017-5507","published":"2017-01-17T00:00:00","updated_at":"2025-08-25T22:34:38.850215+00:00","description":"\nMemory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before\n7.0.4-4 allows remote attackers to cause a denial of service (memory\nconsumption) via vectors involving a pixel cache.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0178-Fix-memory-leak-in-MPC-file-handling.patch"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/16/6","https://ubuntu.com/security/notices/USN-3222-1","https://www.cve.org/CVERecord?id=CVE-2017-5507"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851382"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/4493d9ca1124564da17f9b628ef9d0f1a6be9738"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3222-1"],"notices":[{"id":"USN-3222-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-08T14:02:00.259584","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"}]},"type":"USN","cves_ids":["CVE-2016-10062","CVE-2016-10144","CVE-2016-10145","CVE-2016-10146","CVE-2016-8707","CVE-2017-5506","CVE-2017-5507","CVE-2017-5508","CVE-2017-5510","CVE-2017-5511"]}]},{"id":"CVE-2017-5506","published":"2017-01-17T00:00:00","updated_at":"2025-08-25T22:34:38.850215+00:00","description":"\nDouble free vulnerability in magick/profile.c in ImageMagick allows remote\nattackers to have unspecified impact via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0177-Fix-a-double-free-in-profile-due-to-overflow.patch"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/16/6","https://ubuntu.com/security/notices/USN-3222-1","https://www.cve.org/CVERecord?id=CVE-2017-5506"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/354","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851383"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/6235f1f7a9f7b0f83b197f6cd0073dbb6602d0fb"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3222-1"],"notices":[{"id":"USN-3222-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-03-08T14:02:00.259584","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.8"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.5","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.5","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.4"}]},"type":"USN","cves_ids":["CVE-2016-10062","CVE-2016-10144","CVE-2016-10145","CVE-2016-10146","CVE-2016-8707","CVE-2017-5506","CVE-2017-5507","CVE-2017-5508","CVE-2017-5510","CVE-2017-5511"]}]},{"id":"CVE-2017-0357","published":"2017-01-17T00:00:00","updated_at":"2025-08-25T22:15:37.471227+00:00","description":"\nA heap-overflow flaw exists in the -tr loader of iucode-tool starting with\nv1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"1.4 and higher"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://gitlab.com/iucode-tool/iucode-tool/issues/3","https://ubuntu.com/security/notices/USN-3186-1","https://www.cve.org/CVERecord?id=CVE-2017-0357"],"bugs":[""],"patches":{"iucode-tool":["upstream: https://gitlab.com/iucode-tool/iucode-tool/uploads/2dfd5f52b8dc5c42ad7e52123c535051/iucode-tool_fix-cve-2017-0357.patch","upstream: https://gitlab.com/iucode-tool/iucode-tool/commit/e5e14bfd0427dca80ee19780af57c60eef3577e0"]},"tags":{},"packages":[{"name":"iucode-tool","source":"https://ubuntu.com/security/cve?package=iucode-tool","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iucode-tool","debian":"https://tracker.debian.org/pkg/iucode-tool","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.5.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.6.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.0.1-1]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3186-1"],"notices":[{"id":"USN-3186-1","title":"iucode-tool vulnerability","summary":"iucode-tool could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-01T18:23:17.405395","description":"It was discovered that iucode-tool incorrectly handled certain microcodes\nwhen using the -tr loader. If a user were tricked into processing a\nspecially crafted microcode, a remote attacker could use this issue to\ncause iucode-tool to crash, resulting in a denial of service, or possibly\nexecute arbitrary code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"iucode-tool","version":"1.5.1-1ubuntu0.1","description":"Intel processor microcode tool","is_source":true},{"name":"iucode-tool","version":"1.5.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/iucode-tool","version_link":"https://launchpad.net/ubuntu/+source/iucode-tool/1.5.1-1ubuntu0.1","pocket":"security"}],"yakkety":[{"name":"iucode-tool","version":"1.6.1-1ubuntu0.1","description":"Intel processor microcode tool","is_source":true},{"name":"iucode-tool","version":"1.6.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/iucode-tool","version_link":"https://launchpad.net/ubuntu/+source/iucode-tool/1.6.1-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-0357"]}]},{"id":"CVE-2017-5223","published":"2017-01-16T06:59:00","updated_at":"2025-08-25T22:33:42.790105+00:00","description":"\nAn issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML\nmethod applies transformations to an HTML document to make it usable as an\nemail message body. One of the transformations is to convert relative image\nURLs into attachments using a script-provided base directory. If no base\ndirectory is provided, it resolves to /, meaning that relative image URLs\nget treated as absolute local file paths and added as attachments. To form\na remote vulnerability, the msgHTML method must be called, passed an\nunfiltered, user-supplied HTML document, and must not set a base directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://kalilinux.co/2017/01/12/phpmailer-cve-2017-5223-local-information-disclosure-vulnerability-analysis/","https://github.com/PHPMailer/PHPMailer/blob/master/SECURITY.md","https://ubuntu.com/security/notices/USN-5956-1","https://www.cve.org/CVERecord?id=CVE-2017-5223"],"bugs":[""],"patches":{"libphp-phpmailer":["upstream: https://github.com/PHPMailer/PHPMailer/commit/ad4cb09682682da2217799a0c521d4cdc6753402"]},"tags":{},"packages":[{"name":"libphp-phpmailer","source":"https://ubuntu.com/security/cve?package=libphp-phpmailer","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libphp-phpmailer","debian":"https://tracker.debian.org/pkg/libphp-phpmailer","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"5.2.14+dfsg-2.3+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2.14+dfsg-2.3, 5.2.9+dfsg-2+deb8u2, 5.1-1.3+deb7u1, 5.2.22","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.2.14+dfsg-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-5956-1"],"notices":[{"id":"USN-5956-1","title":"PHPMailer vulnerabilities","summary":"Several security issues were fixed in PHPMailer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-15T14:33:12.444421","description":"Dawid Golunski discovered that PHPMailer was not properly escaping user\ninput data used as arguments to functions executed by the system shell. An\nattacker could possibly use this issue to execute arbitrary code. This\nissue only affected Ubuntu 16.04 ESM. (CVE-2016-10033, CVE-2016-10045)\n\nIt was discovered that PHPMailer was not properly escaping characters\nin certain fields of the code_generator.php example code. An attacker\ncould possibly use this issue to conduct cross-site scripting (XSS)\nattacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04\nESM. (CVE-2017-11503)\n\nYongxiang Li discovered that PHPMailer was not properly converting\nrelative paths provided as user input when adding attachments to messages,\nwhich could lead to relative image URLs being treated as absolute local\nfile paths and added as attachments. An attacker could possibly use this\nissue to access unauthorized resources and expose sensitive information.\nThis issue only affected Ubuntu 16.04 ESM. (CVE-2017-5223)\n\nSehun Oh discovered that PHPMailer was not properly processing untrusted\nnon-local file attachments, which could lead to an object injection. An\nattacker could possibly use this issue to execute arbitrary code. This\nissue only affected Ubuntu 16.04 ESM. (CVE-2018-19296)\n\nElar Lang discovered that PHPMailer was not properly escaping file\nattachment names, which could lead to a misinterpretation of file types\nby entities processing the message. An attacker could possibly use this\nissue to bypass attachment filters. This issue was only fixed in Ubuntu\n16.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-13625)\n\nIt was discovered that PHPMailer was not properly handling callables in\nits validateAddress function, which could result in untrusted code being\ncalled should the global namespace contain a function called 'php'. An\nattacker could possibly use this issue to execute arbitrary code. This\nissue was only fixed in Ubuntu 20.04 ESM and Ubuntu 22.04 ESM.\n(CVE-2021-3603)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"libphp-phpmailer","version":"6.2.0-2ubuntu0.1~esm1","description":"full featured email transfer class for PHP","is_source":true},{"name":"libphp-phpmailer","version":"6.2.0-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libphp-phpmailer","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libphp-phpmailer","version":"6.0.6-0.1ubuntu0.1~esm1","description":"full featured email transfer class for PHP","is_source":true},{"name":"libphp-phpmailer","version":"6.0.6-0.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libphp-phpmailer","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libphp-phpmailer","version":"5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm1","description":"full featured email transfer class for PHP","is_source":true},{"name":"libphp-phpmailer","version":"5.2.14+dfsg-2.3+deb9u2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libphp-phpmailer","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"libphp-phpmailer","version":"5.2.14+dfsg-1ubuntu0.1~esm1","description":"full featured email transfer class for PHP","is_source":true},{"name":"libphp-phpmailer","version":"5.2.14+dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libphp-phpmailer","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-3603","CVE-2016-10045","CVE-2017-5223","CVE-2016-10033","CVE-2018-19296","CVE-2017-11503","CVE-2020-13625"]}]},{"id":"CVE-2017-5493","published":"2017-01-15T02:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nwp-includes/ms-functions.php in the Multisite WordPress API in WordPress\nbefore 4.7.1 does not properly choose random numbers for keys, which makes\nit easier for remote attackers to bypass intended access restrictions via a\ncrafted (1) site signup or (2) user signup.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/14/1","https://wpvulndb.com/vulnerabilities/8721","https://github.com/WordPress/WordPress/commit/cea9e2dc62abf777e06b12ec4ad9d1aaa49b29f4","http://www.openwall.com/lists/oss-security/2017/01/14/6","https://codex.wordpress.org/Version_4.7.1","https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/","https://www.cve.org/CVERecord?id=CVE-2017-5493"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851310"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5492","published":"2017-01-15T02:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in the widget-editing\naccessibility-mode feature in WordPress before 4.7.1 allows remote\nattackers to hijack the authentication of unspecified victims for requests\nthat perform a widgets-access action, related to\nwp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/14/1","https://wpvulndb.com/vulnerabilities/8720","https://github.com/WordPress/WordPress/commit/03e5c0314aeffe6b27f4b98fef842bf0fb00c733","http://www.openwall.com/lists/oss-security/2017/01/14/6","https://codex.wordpress.org/Version_4.7.1","https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/","https://www.cve.org/CVERecord?id=CVE-2017-5492"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851310"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5491","published":"2017-01-15T02:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nwp-mail.php in WordPress before 4.7.1 might allow remote attackers to\nbypass intended posting restrictions via a spoofed mail server with the\nmail.example.com name.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/14/1","https://wpvulndb.com/vulnerabilities/8719","https://github.com/WordPress/WordPress/commit/061e8788814ac87706d8b95688df276fe3c8596a","http://www.openwall.com/lists/oss-security/2017/01/14/6","https://codex.wordpress.org/Version_4.7.1","https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/","https://www.cve.org/CVERecord?id=CVE-2017-5491"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851310"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5490","published":"2017-01-15T02:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nCross-site scripting (XSS) vulnerability in the theme-name fallback\nfunctionality in wp-includes/class-wp-theme.php in WordPress before 4.7.1\nallows remote attackers to inject arbitrary web script or HTML via a\ncrafted directory name of a theme, related to\nwp-admin/includes/class-theme-installer-skin.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/14/1","https://wpvulndb.com/vulnerabilities/8718","https://github.com/WordPress/WordPress/commit/ce7fb2934dd111e6353784852de8aea2a938b359","http://www.openwall.com/lists/oss-security/2017/01/14/6","https://codex.wordpress.org/Version_4.7.1","https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/","https://www.mehmetince.net/low-severity-wordpress/","https://www.cve.org/CVERecord?id=CVE-2017-5490"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851310"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5489","published":"2017-01-15T02:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1\nallows remote attackers to hijack the authentication of unspecified victims\nvia vectors involving a Flash file upload.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/14/1","https://wpvulndb.com/vulnerabilities/8717","http://www.openwall.com/lists/oss-security/2017/01/14/6","https://codex.wordpress.org/Version_4.7.1","https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/","https://www.cve.org/CVERecord?id=CVE-2017-5489"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851310"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5488","published":"2017-01-15T02:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in\nwp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers\nto inject arbitrary web script or HTML via the (1) name or (2) version\nheader of a plugin.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/14/1","https://wpvulndb.com/vulnerabilities/8716","https://github.com/WordPress/WordPress/blob/c9ea1de1441bb3bda133bf72d513ca9de66566c2/wp-admin/update-core.php","http://www.openwall.com/lists/oss-security/2017/01/14/6","https://codex.wordpress.org/Version_4.7.1","https://github.com/WordPress/WordPress/commit/c9ea1de1441bb3bda133bf72d513ca9de66566c2","https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/","https://www.cve.org/CVERecord?id=CVE-2017-5488"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851310"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5487","published":"2017-01-15T02:59:00","updated_at":"2025-08-25T22:34:34.257765+00:00","description":"\nwp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the\nREST API implementation in WordPress 4.7 before 4.7.1 does not properly\nrestrict listings of post authors, which allows remote attackers to obtain\nsensitive information via a wp-json/wp/v2/users request.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"Vulnerable code introduced in v4.7"}],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/14/1","https://wpvulndb.com/vulnerabilities/8715","https://github.com/WordPress/WordPress/commit/daf358983cc1ce0c77bf6d2de2ebbb43df2add60","http://www.openwall.com/lists/oss-security/2017/01/14/6","https://codex.wordpress.org/Version_4.7.1","https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/","https://www.wordfence.com/blog/2016/12/wordfence-blocks-username-harvesting-via-new-rest-api-wp-4-7/","https://www.cve.org/CVERecord?id=CVE-2017-5487"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851310"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.7.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":58820,"limit":20,"total_results":79316}