{"cves":[{"id":"CVE-2016-9444","published":"2017-01-11T00:00:00","updated_at":"2025-08-25T22:13:58.867059+00:00","description":"\nnamed in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x\nbefore 9.11.0-P2 allows remote attackers to cause a denial of service\n(assertion failure and daemon exit) via a crafted DS resource record in an\nanswer.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"doesn't affect precise, introduced in 9.8.5"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://kb.isc.org/article/AA-01441/0","https://ubuntu.com/security/notices/USN-3172-1","https://www.cve.org/CVERecord?id=CVE-2016-9444"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"precise","status":"not-affected","description":"1:9.8.1.dfsg.P1-4ubuntu0.19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:9.9.5.dfsg-3ubuntu0.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:9.10.3.dfsg.P4-8ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:9.10.3.dfsg.P4-10.1ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3172-1"],"notices":[{"id":"USN-3172-1","title":"Bind vulnerabilities","summary":"Several security issues were fixed in Bind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-01-12T12:37:04.913044","description":"It was discovered that Bind incorrectly handled certain malformed responses\nto an ANY query. A remote attacker could possibly use this issue to cause\nBind to crash, resulting in a denial of service. (CVE-2016-9131)\n\nIt was discovered that Bind incorrectly handled certain malformed responses\nto an ANY query. A remote attacker could possibly use this issue to cause\nBind to crash, resulting in a denial of service. (CVE-2016-9147)\n\nIt was discovered that Bind incorrectly handled certain malformed DS record\nresponses. A remote attacker could possibly use this issue to cause Bind to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444)\n","is_hidden":false,"release_packages":{"precise":[{"name":"bind9","version":"1:9.8.1.dfsg.P1-4ubuntu0.20","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.8.1.dfsg.P1-4ubuntu0.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.8.1.dfsg.P1-4ubuntu0.20"}],"trusty":[{"name":"bind9","version":"1:9.9.5.dfsg-3ubuntu0.11","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9-doc","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9-host","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9utils","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"dnsutils","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"host","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libbind-dev","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libbind9-90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libdns100","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisc95","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisccc90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisccfg90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"liblwres90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"lwresd","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"}],"xenial":[{"name":"bind9","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9-doc","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9-host","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9utils","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"dnsutils","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"host","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind-dev","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind-export-dev","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind9-140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns-export162","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns-export162-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns162","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs-export141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs-export141-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc-export160","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc-export160-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc160","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc-export140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc-export140-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg-export140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg-export140-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"liblwres141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"lwresd","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"}],"yakkety":[{"name":"bind9","version":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-10.1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2016-9131","CVE-2016-9147","CVE-2016-9444"]}]},{"id":"CVE-2016-9147","published":"2017-01-11T00:00:00","updated_at":"2025-08-25T22:13:20.674390+00:00","description":"\nnamed in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows\nremote attackers to cause a denial of service (assertion failure and daemon\nexit) via a response containing an inconsistency among the DNSSEC-related\nRRsets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://kb.isc.org/article/AA-01440/0","https://ubuntu.com/security/notices/USN-3172-1","https://www.cve.org/CVERecord?id=CVE-2016-9147"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"precise","status":"released","description":"1:9.8.1.dfsg.P1-4ubuntu0.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:9.9.5.dfsg-3ubuntu0.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:9.10.3.dfsg.P4-8ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:9.10.3.dfsg.P4-10.1ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3172-1"],"notices":[{"id":"USN-3172-1","title":"Bind vulnerabilities","summary":"Several security issues were fixed in Bind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-01-12T12:37:04.913044","description":"It was discovered that Bind incorrectly handled certain malformed responses\nto an ANY query. A remote attacker could possibly use this issue to cause\nBind to crash, resulting in a denial of service. (CVE-2016-9131)\n\nIt was discovered that Bind incorrectly handled certain malformed responses\nto an ANY query. A remote attacker could possibly use this issue to cause\nBind to crash, resulting in a denial of service. (CVE-2016-9147)\n\nIt was discovered that Bind incorrectly handled certain malformed DS record\nresponses. A remote attacker could possibly use this issue to cause Bind to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444)\n","is_hidden":false,"release_packages":{"precise":[{"name":"bind9","version":"1:9.8.1.dfsg.P1-4ubuntu0.20","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.8.1.dfsg.P1-4ubuntu0.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.8.1.dfsg.P1-4ubuntu0.20"}],"trusty":[{"name":"bind9","version":"1:9.9.5.dfsg-3ubuntu0.11","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9-doc","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9-host","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9utils","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"dnsutils","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"host","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libbind-dev","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libbind9-90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libdns100","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisc95","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisccc90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisccfg90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"liblwres90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"lwresd","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"}],"xenial":[{"name":"bind9","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9-doc","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9-host","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9utils","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"dnsutils","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"host","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind-dev","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind-export-dev","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind9-140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns-export162","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns-export162-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns162","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs-export141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs-export141-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc-export160","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc-export160-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc160","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc-export140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc-export140-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg-export140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg-export140-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"liblwres141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"lwresd","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"}],"yakkety":[{"name":"bind9","version":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-10.1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2016-9131","CVE-2016-9147","CVE-2016-9444"]}]},{"id":"CVE-2016-9131","published":"2017-01-11T00:00:00","updated_at":"2025-08-25T22:13:20.674390+00:00","description":"\nnamed in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x\nbefore 9.11.0-P2 allows remote attackers to cause a denial of service\n(assertion failure and daemon exit) via a malformed response to an RTYPE\nANY query.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://kb.isc.org/article/AA-01439/0","https://ubuntu.com/security/notices/USN-3172-1","https://www.cve.org/CVERecord?id=CVE-2016-9131"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"precise","status":"released","description":"1:9.8.1.dfsg.P1-4ubuntu0.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:9.9.5.dfsg-3ubuntu0.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:9.10.3.dfsg.P4-8ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:9.10.3.dfsg.P4-10.1ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3172-1"],"notices":[{"id":"USN-3172-1","title":"Bind vulnerabilities","summary":"Several security issues were fixed in Bind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-01-12T12:37:04.913044","description":"It was discovered that Bind incorrectly handled certain malformed responses\nto an ANY query. A remote attacker could possibly use this issue to cause\nBind to crash, resulting in a denial of service. (CVE-2016-9131)\n\nIt was discovered that Bind incorrectly handled certain malformed responses\nto an ANY query. A remote attacker could possibly use this issue to cause\nBind to crash, resulting in a denial of service. (CVE-2016-9147)\n\nIt was discovered that Bind incorrectly handled certain malformed DS record\nresponses. A remote attacker could possibly use this issue to cause Bind to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-9444)\n","is_hidden":false,"release_packages":{"precise":[{"name":"bind9","version":"1:9.8.1.dfsg.P1-4ubuntu0.20","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.8.1.dfsg.P1-4ubuntu0.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.8.1.dfsg.P1-4ubuntu0.20"}],"trusty":[{"name":"bind9","version":"1:9.9.5.dfsg-3ubuntu0.11","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9-doc","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9-host","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"bind9utils","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"dnsutils","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"host","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libbind-dev","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libbind9-90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libdns100","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisc95","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisccc90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"libisccfg90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"liblwres90","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"},{"name":"lwresd","version":"1:9.9.5.dfsg-3ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.11","pocket":"security"}],"xenial":[{"name":"bind9","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9-doc","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9-host","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"bind9utils","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"dnsutils","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"host","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind-dev","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind-export-dev","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libbind9-140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns-export162","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns-export162-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libdns162","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs-export141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs-export141-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libirs141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc-export160","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc-export160-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisc160","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc-export140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc-export140-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccc140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg-export140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg-export140-udeb","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"libisccfg140","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"liblwres141","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"},{"name":"lwresd","version":"1:9.10.3.dfsg.P4-8ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.4","pocket":"security"}],"yakkety":[{"name":"bind9","version":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.10.3.dfsg.P4-10.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-10.1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2016-9131","CVE-2016-9147","CVE-2016-9444"]}]},{"id":"CVE-2016-7479","published":"2017-01-11T00:00:00","updated_at":"2025-08-25T22:10:25.920509+00:00","description":"\nIn all versions of PHP 7, during the unserialization process, resizing the\n'properties' hash table of a serialized object may lead to use-after-free.\nA remote attacker may exploit this bug to gain arbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://blog.checkpoint.com/2016/12/27/check-point-discovers-three-zero-day-vulnerabilities-web-programming-language-php-7","http://blog.checkpoint.com/wp-content/uploads/2016/12/PHP_Technical_Report.pdf","https://www.youtube.com/watch?v=LDcaPstAuPk","https://ubuntu.com/security/notices/USN-3196-1","https://ubuntu.com/security/notices/USN-3211-1","https://www.cve.org/CVERecord?id=CVE-2016-7479"],"bugs":["https://bugs.php.net/bug.php?id=73092","https://bugs.php.net/bug.php?id=72610"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=0426b916df396a23e5c34514e4f2f0627efdcdf0"],"php7.0":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=0426b916df396a23e5c34514e4f2f0627efdcdf0","upstream: http://git.php.net/?p=php-src.git;a=commit;h=b47c49d7a00bc34d7e0f3d72732f66e904da6fa7"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.26","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.21","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.0.15-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"7.0.15-0ubuntu0.16.10.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3211-1","USN-3196-1"],"notices":[{"id":"USN-3211-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2017-02-23T16:28:50.023036","description":"It was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2016-7479)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2016-9137)\n\nIt was discovered that PHP incorrectly handled unserializing certain\nwddxPacket XML documents. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-9935)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2016-9936)\n\nIt was discovered that PHP incorrectly handled certain EXIF data. A remote\nattacker could use this issue to cause PHP to crash, resulting in a denial\nof service. (CVE-2016-10158)\n\nIt was discovered that PHP incorrectly handled certain PHAR archives. A\nremote attacker could use this issue to cause PHP to crash or consume\nresources, resulting in a denial of service. (CVE-2016-10159)\n\nIt was discovered that PHP incorrectly handled certain PHAR archives. A\nremote attacker could use this issue to cause PHP to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-10160)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service. (CVE-2016-10161)\n\nIt was discovered that PHP incorrectly handled unserializing certain\nwddxPacket XML documents. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service. (CVE-2016-10162)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2017-5340)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"php7.0","version":"7.0.15-0ubuntu0.16.04.2","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php7.0","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"libphp7.0-embed","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-bcmath","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-bz2","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-cgi","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-cli","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-common","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-curl","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-dba","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-dev","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-enchant","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-fpm","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-gd","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-gmp","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-imap","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-interbase","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-intl","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-json","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-ldap","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-mbstring","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-mcrypt","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-mysql","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-odbc","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-opcache","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-pgsql","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-phpdbg","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-pspell","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-readline","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-recode","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-snmp","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-soap","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-sqlite3","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-sybase","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-tidy","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-xml","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-xmlrpc","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-xsl","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"},{"name":"php7.0-zip","version":"7.0.15-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.04.2","pocket":"security"}],"yakkety":[{"name":"php7.0","version":"7.0.15-0ubuntu0.16.10.2","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php7.0","version":"7.0.15-0ubuntu0.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.10.2"},{"name":"php7.0-cgi","version":"7.0.15-0ubuntu0.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.10.2"},{"name":"php7.0-cli","version":"7.0.15-0ubuntu0.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.10.2"},{"name":"php7.0-fpm","version":"7.0.15-0ubuntu0.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.15-0ubuntu0.16.10.2"}]},"type":"USN","cves_ids":["CVE-2016-7479","CVE-2016-9137","CVE-2016-9935","CVE-2016-9936","CVE-2016-10158","CVE-2016-10159","CVE-2016-10160","CVE-2016-10161","CVE-2016-10162","CVE-2017-5340"]},{"id":"USN-3196-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-14T18:44:56.157767","description":"It was discovered that PHP incorrectly handled certain arguments to the\nlocale_get_display_name function. A remote attacker could use this issue to\ncause PHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2014-9912)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\nhang, resulting in a denial of service. (CVE-2016-7478)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2016-7479)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only applied to Ubuntu 14.04 LTS. (CVE-2016-9137)\n\nIt was discovered that PHP incorrectly handled unserializing certain\nwddxPacket XML documents. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service. (CVE-2016-9934)\n\nIt was discovered that PHP incorrectly handled unserializing certain\nwddxPacket XML documents. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-9935)\n\nIt was discovered that PHP incorrectly handled certain EXIF data. A remote\nattacker could use this issue to cause PHP to crash, resulting in a denial\nof service. (CVE-2016-10158)\n\nIt was discovered that PHP incorrectly handled certain PHAR archives. A\nremote attacker could use this issue to cause PHP to crash or consume\nresources, resulting in a denial of service. (CVE-2016-10159)\n\nIt was discovered that PHP incorrectly handled certain PHAR archives. A\nremote attacker could use this issue to cause PHP to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-10160)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service. (CVE-2016-10161)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.26","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.21","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-9912","CVE-2016-10158","CVE-2016-10159","CVE-2016-10160","CVE-2016-10161","CVE-2016-7478","CVE-2016-7479","CVE-2016-9137","CVE-2016-9934","CVE-2016-9935"]}]},{"id":"CVE-2016-7478","published":"2017-01-11T00:00:00","updated_at":"2025-08-25T22:10:21.382492+00:00","description":"\nZend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before\n7.0.13, allows remote attackers to cause a denial of service (infinite\nloop) via a crafted Exception object in serialized data, a related issue to\nCVE-2015-8876.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"can't reproduce with 7.0.13, assumed fixed\nphp5 needs CVE-2016-9137 to be applied"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://blog.checkpoint.com/2016/12/27/check-point-discovers-three-zero-day-vulnerabilities-web-programming-language-php-7","http://blog.checkpoint.com/wp-content/uploads/2016/12/PHP_Technical_Report.pdf","https://www.youtube.com/watch?v=LDcaPstAuPk","https://ubuntu.com/security/notices/USN-3196-1","https://www.cve.org/CVERecord?id=CVE-2016-7478"],"bugs":["https://bugs.php.net/bug.php?id=73093"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=40e7baab3c90001beee4c8f0ed0ef79ad18ee0d6"],"php7.0":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=eca84946a4e7269d59ea2d79b5f42117de89ae74"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.26","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.21","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.0.13-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.0.13-0ubuntu0.16.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3196-1"],"notices":[{"id":"USN-3196-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-02-14T18:44:56.157767","description":"It was discovered that PHP incorrectly handled certain arguments to the\nlocale_get_display_name function. A remote attacker could use this issue to\ncause PHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2014-9912)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\nhang, resulting in a denial of service. (CVE-2016-7478)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2016-7479)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only applied to Ubuntu 14.04 LTS. (CVE-2016-9137)\n\nIt was discovered that PHP incorrectly handled unserializing certain\nwddxPacket XML documents. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service. (CVE-2016-9934)\n\nIt was discovered that PHP incorrectly handled unserializing certain\nwddxPacket XML documents. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-9935)\n\nIt was discovered that PHP incorrectly handled certain EXIF data. A remote\nattacker could use this issue to cause PHP to crash, resulting in a denial\nof service. (CVE-2016-10158)\n\nIt was discovered that PHP incorrectly handled certain PHAR archives. A\nremote attacker could use this issue to cause PHP to crash or consume\nresources, resulting in a denial of service. (CVE-2016-10159)\n\nIt was discovered that PHP incorrectly handled certain PHAR archives. A\nremote attacker could use this issue to cause PHP to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-10160)\n\nIt was discovered that PHP incorrectly handled certain invalid objects when\nunserializing data. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service. (CVE-2016-10161)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.26","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.26"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.21","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.21","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-9912","CVE-2016-10158","CVE-2016-10159","CVE-2016-10160","CVE-2016-10161","CVE-2016-7478","CVE-2016-7479","CVE-2016-9137","CVE-2016-9934","CVE-2016-9935"]}]},{"id":"CVE-2016-6837","published":"2017-01-10T15:59:00","updated_at":"2025-08-25T22:09:07.406919+00:00","description":"\nCross-site scripting (XSS) vulnerability in MantisBT Filter API in MantisBT\nversions before 1.2.19, and versions 2.0.0-beta1, 1.3.0-beta1 allows remote\nattackers to inject arbitrary web script or HTML via the 'view_type'\nparameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://mantisbt.org/bugs/view.php?id=21611","https://www.cve.org/CVERecord?id=CVE-2016-6837"],"bugs":[""],"patches":{"mantis":["upstream: https://github.com/mantisbt/mantisbt/commit/7086c2d8b4b20ac14013b36761ac04f0abf21a4e"]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-6831","published":"2017-01-10T15:59:00","updated_at":"2025-08-26T11:55:44.268386+00:00","description":"\nThe \"process-execute\" and \"process-spawn\" procedures did not free memory\ncorrectly when the execve() call failed, resulting in a memory leak. This\ncould be abused by an attacker to cause resource exhaustion or a denial of\nservice. This affects all releases of CHICKEN up to and including 4.11 (it\nwill be fixed in 4.12 and 5.0, which are not yet released).","ubuntu_description":"","notes":[{"author":"ratliff","note":"Fixed in same upstream patch as CVE-2016-6830"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/08/18/2","https://www.cve.org/CVERecord?id=CVE-2016-6831"],"bugs":[""],"patches":{"chicken":[]},"tags":{},"packages":[{"name":"chicken","source":"https://ubuntu.com/security/cve?package=chicken","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chicken","debian":"https://tracker.debian.org/pkg/chicken","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4.7.0-1+deb7u1build0.12.04.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-6830","published":"2017-01-10T15:59:00","updated_at":"2025-08-26T11:55:44.268386+00:00","description":"\nThe \"process-execute\" and \"process-spawn\" procedures in CHICKEN Scheme used\nfixed-size buffers for holding the arguments and environment variables to\nuse in its execve() call. This would allow user-supplied\nargument/environment variable lists to trigger a buffer overrun. This\naffects all releases of CHICKEN up to and including 4.11 (it will be fixed\nin 4.12 and 5.0, which are not yet released).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://lists.nongnu.org/archive/html/chicken-announce/2016-08/msg00001.html","http://www.openwall.com/lists/oss-security/2016/08/18/2","https://www.cve.org/CVERecord?id=CVE-2016-6830"],"bugs":[""],"patches":{"chicken":["upstream: http://lists.nongnu.org/archive/html/chicken-hackers/2016-07/txtSWHYeFeG0R.txt"]},"tags":{},"packages":[{"name":"chicken","source":"https://ubuntu.com/security/cve?package=chicken","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chicken","debian":"https://tracker.debian.org/pkg/chicken","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4.7.0-1+deb7u1build0.12.04.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.12.0-0.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-6581","published":"2017-01-10T15:59:00","updated_at":"2025-08-26T11:55:44.268386+00:00","description":"\nA HTTP/2 implementation built using any version of the Python HPACK library\nbetween v1.0.0 and v2.2.0 could be targeted for a denial of service attack,\nspecifically a so-called \"HPACK Bomb\" attack. This attack occurs when an\nattacker inserts a header field that is exactly the size of the HPACK\ndynamic header table into the dynamic header table. The attacker can then\nsend a header block that is simply repeated requests to expand that field\nin the dynamic table. This can lead to a gigantic compression ratio of\n4,096 or better, meaning that 16kB of data can decompress to 64MB of data\non the target machine.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/python-hyper/hpack/pull/56","http://www.openwall.com/lists/oss-security/2016/08/04/3","https://www.cve.org/CVERecord?id=CVE-2016-6581"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833467"],"patches":{"python-hpack":[]},"tags":{},"packages":[{"name":"python-hpack","source":"https://ubuntu.com/security/cve?package=python-hpack","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-hpack","debian":"https://tracker.debian.org/pkg/python-hpack","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5208","published":"2017-01-09T00:00:00","updated_at":"2025-08-25T22:33:37.708044+00:00","description":"\nInteger overflow in the wrestool program in icoutils before 0.31.1 allows\nremote attackers to cause a denial of service (memory corruption) via a\ncrafted executable, which triggers a denial of service (application crash)\nor the possibility of execution of arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/08/1","https://ubuntu.com/security/notices/USN-3178-1","https://ubuntu.com/security/notices/USN-4695-1","https://www.cve.org/CVERecord?id=CVE-2017-5208"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017"],"patches":{"icoutils":["upstream: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=0d569f458f306b88f60156d60c9cf058125cf173"]},"tags":{},"packages":[{"name":"icoutils","source":"https://ubuntu.com/security/cve?package=icoutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=icoutils","debian":"https://tracker.debian.org/pkg/icoutils","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.29.1-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.31.0-2+deb8u2build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.31.0-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.31.0-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.31.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3178-1","USN-4695-1"],"notices":[{"id":"USN-3178-1","title":"icoutils vulnerabilities","summary":"icoutils could be made to crash or run programs as your login if it opened\na specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-01-24T20:02:30.271948","description":"It was discovered that icoutils incorrectly handled memory when processing\ncertain files. If a user or automated system were tricked into opening a\nspecially crafted file, an attacker could cause icoutils to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"icoutils","version":"0.29.1-2ubuntu0.1","description":"Create and extract MS Windows icons and cursors","is_source":true},{"name":"icoutils","version":"0.29.1-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/icoutils","version_link":"https://launchpad.net/ubuntu/+source/icoutils/0.29.1-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-5208","CVE-2017-5331","CVE-2017-5332","CVE-2017-5333"]},{"id":"USN-4695-1","title":"icoutils vulnerabilities","summary":"Several security issues were fixed in icoutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-01-18T12:30:38.357335","description":"Choongwoo Han discovered that icoutils incorrectly handled certain files.\nAn attacker could possibly use this issue to cause a denial of service\nor execute arbitrary code. (CVE-2017-5208)\n\nIt was discovered that icoutils incorrectly handled certain files.\nAn attacker could possibly use this issue to cause a denial of service\nor execute arbitrary code. (CVE-2017-5331, CVE-2017-5332, CVE-2017-5333)\n\nJerzy Kramarz discovered that icoutils incorrectly handled certain files.\nAn attacker could possibly use this issue to cause a crash or execute\narbitrary code. (CVE-2017-6009, CVE-2017-6010)\n\nJerzy Kramarz discovered that icoutils incorrectly handled certain files.\nAn attacker could possibly use this issue to expose sensitive information.\n(CVE-2017-6011)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"icoutils","version":"0.31.0-3ubuntu0.1","description":"Create and extract MS Windows icons and cursors","is_source":true},{"name":"icoutils","version":"0.31.0-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/icoutils","version_link":"https://launchpad.net/ubuntu/+source/icoutils/0.31.0-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-5332","CVE-2017-6011","CVE-2017-6009","CVE-2017-5331","CVE-2017-6010","CVE-2017-5208","CVE-2017-5333"]}]},{"id":"CVE-2016-10124","published":"2017-01-09T00:00:00","updated_at":"2025-08-25T21:52:32.645216+00:00","description":"\nAn issue was discovered in Linux Containers (LXC) before 2016-02-22. When\nexecuting a program via lxc-attach, the nonpriv session can escape to the\nparent session by using the TIOCSTI ioctl to push characters into the\nterminal's input buffer, allowing an attacker to escape the container.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3375-1","https://www.cve.org/CVERecord?id=CVE-2016-10124"],"bugs":[""],"patches":{"lxc":["upstream: https://github.com/lxc/lxc/commit/e986ea3dfa4a2957f71ae9bfaed406dd6e1ffff6","upstream: https://github.com/lxc/lxc/commit/5eacdc3dbd0e45abf3cc90cf0216a7f8ee560abf"]},"tags":{},"packages":[{"name":"lxc","source":"https://ubuntu.com/security/cve?package=lxc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxc","debian":"https://tracker.debian.org/pkg/lxc","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.10-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:2.0.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.0.7-0ubuntu1~16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.0.7-0ubuntu1~16.10.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.0.7-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3375-1"],"notices":[{"id":"USN-3375-1","title":"LXC vulnerability","summary":"LXC would allow unintended access.\n","instructions":"After a standard system update you need to restart LXC containers to make\nall the necessary changes.\n","references":[],"published":"2017-08-02T12:35:47.602601","description":"It was discovered that LXC incorrectly handled the TIOCSTI ioctl. An\nattacker could possibly use this issue to escape LXC containers.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"lxc","version":"1.0.10-0ubuntu1.1","description":"Linux Containers userspace tools","is_source":true},{"name":"liblxc1","version":"1.0.10-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxc","version_link":"https://launchpad.net/ubuntu/+source/lxc/1.0.10-0ubuntu1.1","pocket":"security"},{"name":"lxc","version":"1.0.10-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxc","version_link":"https://launchpad.net/ubuntu/+source/lxc/1.0.10-0ubuntu1.1","pocket":"security"},{"name":"lxc-dev","version":"1.0.10-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxc","version_link":"https://launchpad.net/ubuntu/+source/lxc/1.0.10-0ubuntu1.1","pocket":"security"},{"name":"lxc-templates","version":"1.0.10-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxc","version_link":"https://launchpad.net/ubuntu/+source/lxc/1.0.10-0ubuntu1.1","pocket":"security"},{"name":"lxc-tests","version":"1.0.10-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxc","version_link":"https://launchpad.net/ubuntu/+source/lxc/1.0.10-0ubuntu1.1","pocket":"security"},{"name":"python3-lxc","version":"1.0.10-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxc","version_link":"https://launchpad.net/ubuntu/+source/lxc/1.0.10-0ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10124"]}]},{"id":"CVE-2016-2336","published":"2017-01-06T21:59:00","updated_at":"2025-08-25T21:57:09.714865+00:00","description":"\nType confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke\nand ole_query_interface. Attacker passing different type of object than\nthis assumed by developers can cause arbitrary code execution.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"win32ole not in binary package"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.talosintelligence.com/reports/TALOS-2016-0029/","https://www.cve.org/CVERecord?id=CVE-2016-2336"],"bugs":[""],"patches":{"ruby2.3":[]},"tags":{},"packages":[{"name":"ruby2.3","source":"https://ubuntu.com/security/cve?package=ruby2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby2.3","debian":"https://tracker.debian.org/pkg/ruby2.3","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1549","published":"2017-01-06T21:59:00","updated_at":"2025-08-25T21:54:17.295459+00:00","description":"\nA malicious authenticated peer can create arbitrarily-many ephemeral\nassociations in order to win the clock selection algorithm in ntpd in NTP\n4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and\na5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream proposes mitigation only"}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security","http://www.talosintel.com/reports/TALOS-2016-0083/","https://www.cve.org/CVERecord?id=CVE-2016-1549"],"bugs":["http://support.ntp.org/bin/view/Main/NtpBug3012"],"patches":{"ntp":[]},"tags":{},"packages":[{"name":"ntp","source":"https://ubuntu.com/security/cve?package=ntp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ntp","debian":"https://tracker.debian.org/pkg/ntp","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:4.2.8p7+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1515","published":"2017-01-06T21:59:00","updated_at":"2025-08-04T19:24:32.789323+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs:\nCVE-2015-8789.  Reason: This candidate is a reservation duplicate of\nCVE-2015-8789.  Notes: All CVE users should reference CVE-2015-8789 instead\nof this candidate.  All references and descriptions in this candidate have\nbeen removed to prevent accidental usage","ubuntu_description":"","notes":[{"author":"sbeattie","note":"mkvtoolnix contains an embedded copy of libebml, but looks to\nuse the system version\nduplicate of CVE-2015-8789, see http://seclists.org/oss-sec/2017/q1/91"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.talosintelligence.com/reports/TALOS-2016-0037/","https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00046.html","https://www.cve.org/CVERecord?id=CVE-2016-1515"],"bugs":[""],"patches":{"libebml":[],"mkvtoolnix":[]},"tags":{},"packages":[{"name":"libebml","source":"https://ubuntu.com/security/cve?package=libebml","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libebml","debian":"https://tracker.debian.org/pkg/libebml","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"mkvtoolnix","source":"https://ubuntu.com/security/cve?package=mkvtoolnix","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mkvtoolnix","debian":"https://tracker.debian.org/pkg/mkvtoolnix","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1514","published":"2017-01-06T21:59:00","updated_at":"2025-08-04T19:24:32.789323+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs:\nCVE-2015-8790.  Reason: This candidate is a reservation duplicate of\nCVE-2015-8790.  Notes: All CVE users should reference CVE-2015-8790 instead\nof this candidate.  All references and descriptions in this candidate have\nbeen removed to prevent accidental usage","ubuntu_description":"","notes":[{"author":"sbeattie","note":"mkvtoolnix contains an embedded copy of libebml, but it looks\nlike it uses the system version of it\nduplicate of CVE-2015-8790, see http://seclists.org/oss-sec/2017/q1/91"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.talosintelligence.com/reports/TALOS-2016-0036/","https://lists.opensuse.org/opensuse-security-announce/2016-06/msg00046.html","https://www.cve.org/CVERecord?id=CVE-2016-1514"],"bugs":[""],"patches":{"mkvtoolnix":[],"libebml":[]},"tags":{},"packages":[{"name":"libebml","source":"https://ubuntu.com/security/cve?package=libebml","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libebml","debian":"https://tracker.debian.org/pkg/libebml","statuses":[{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"mkvtoolnix","source":"https://ubuntu.com/security/cve?package=mkvtoolnix","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mkvtoolnix","debian":"https://tracker.debian.org/pkg/mkvtoolnix","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7848","published":"2017-01-06T21:59:00","updated_at":"2025-08-25T21:46:18.957100+00:00","description":"\nAn integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds\nmemory copy operation when processing a specially crafted private mode\npacket. The crafted packet needs to have the correct message authentication\ncode and a valid timestamp. When processed by the NTP daemon, it leads to\nan immediate crash.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code in precise-wily doesn't look vulnerable"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_Security_Vulner","http://blog.talosintel.com/2015/10/ntpd-vulnerabilities.html","http://talosintel.com/reports/TALOS-2015-0052/","https://www.cve.org/CVERecord?id=CVE-2015-7848"],"bugs":["http://bugs.ntp.org/show_bug.cgi?id=2913"],"patches":{"ntp":["upstream: https://github.com/ntp-project/ntp/commit/c04c3d3d940dfe1a53132925c4f51aef017d2e0f"]},"tags":{},"packages":[{"name":"ntp","source":"https://ubuntu.com/security/cve?package=ntp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ntp","debian":"https://tracker.debian.org/pkg/ntp","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5196","published":"2017-01-06T00:00:00","updated_at":"2025-08-25T22:33:37.708044+00:00","description":"\nIrssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of\nservice (out-of-bounds read and crash) via vectors involving strings that\nare not UTF8.","ubuntu_description":"","notes":[{"author":"mdeslar","note":"0.8.18 and later only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/05/2","https://irssi.org/security/irssi_sa_2017_01.txt","https://ubuntu.com/security/notices/USN-3184-1","https://www.cve.org/CVERecord?id=CVE-2017-5196"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850403"],"patches":{"irssi":["upstream: https://github.com/irssi/irssi/commit/6c6c42e3d1b49d90aacc0b67f8540471cae02a1d"]},"tags":{},"packages":[{"name":"irssi","source":"https://ubuntu.com/security/cve?package=irssi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi","debian":"https://tracker.debian.org/pkg/irssi","statuses":[{"release_codename":"precise","status":"not-affected","description":"0.8.15-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.21-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.19-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.8.19-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.8.15-5ubuntu3]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3184-1"],"notices":[{"id":"USN-3184-1","title":"Irssi vulnerabilities","summary":"Several security issues were fixed in Irssi.\n","instructions":"After a standard system update you need to restart Irssi to make all the\nnecessary changes.\n","references":[],"published":"2017-02-01T18:08:38.780283","description":"It was discovered that the Irssi buf.pl script set incorrect permissions. A\nlocal attacker could use this issue to retrieve another user's window\ncontents. (CVE-2016-7553)\n\nJoseph Bisch discovered that Irssi incorrectly handled comparing nicks. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5193)\n\nIt was discovered that Irssi incorrectly handled invalid nick messages. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5194)\n\nJoseph Bisch discovered that Irssi incorrectly handled certain incomplete\ncontrol codes. A remote attacker could use this issue to cause Irssi to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS and Ubuntu 16.10.\n(CVE-2017-5195)\n\nHanno Böck and Joseph Bisch discovered that Irssi incorrectly handled\ncertain incomplete character sequences. A remote attacker could use this\nissue to cause Irssi to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2017-5196)\n\nHanno Böck discovered that Irssi incorrectly handled certain format\nstrings. A remote attacker could use this issue to cause Irssi to crash,\nresulting in a denial of service. (CVE-2017-5356)\n","is_hidden":false,"release_packages":{"precise":[{"name":"irssi","version":"0.8.15-4ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-4ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-4ubuntu3.1"}],"trusty":[{"name":"irssi","version":"0.8.15-5ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"},{"name":"irssi-dev","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"}],"xenial":[{"name":"irssi","version":"0.8.19-1ubuntu1.3","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"},{"name":"irssi-dev","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"}],"yakkety":[{"name":"irssi","version":"0.8.19-1ubuntu2.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2016-7553","CVE-2017-5193","CVE-2017-5194","CVE-2017-5195","CVE-2017-5196","CVE-2017-5356"]}]},{"id":"CVE-2017-5195","published":"2017-01-06T00:00:00","updated_at":"2025-08-25T22:33:37.708044+00:00","description":"\nIrssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of\nservice (out-of-bounds read and crash) via a crafted ANSI x8 color code.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"0.8.17 and later only"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/05/2","https://irssi.org/security/irssi_sa_2017_01.txt","https://ubuntu.com/security/notices/USN-3184-1","https://www.cve.org/CVERecord?id=CVE-2017-5195"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850403"],"patches":{"irssi":["upstream: https://github.com/irssi/irssi/commit/6c6c42e3d1b49d90aacc0b67f8540471cae02a1d"]},"tags":{},"packages":[{"name":"irssi","source":"https://ubuntu.com/security/cve?package=irssi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi","debian":"https://tracker.debian.org/pkg/irssi","statuses":[{"release_codename":"precise","status":"not-affected","description":"0.8.15-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.21-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.19-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.8.19-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.8.15-5ubuntu3]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3184-1"],"notices":[{"id":"USN-3184-1","title":"Irssi vulnerabilities","summary":"Several security issues were fixed in Irssi.\n","instructions":"After a standard system update you need to restart Irssi to make all the\nnecessary changes.\n","references":[],"published":"2017-02-01T18:08:38.780283","description":"It was discovered that the Irssi buf.pl script set incorrect permissions. A\nlocal attacker could use this issue to retrieve another user's window\ncontents. (CVE-2016-7553)\n\nJoseph Bisch discovered that Irssi incorrectly handled comparing nicks. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5193)\n\nIt was discovered that Irssi incorrectly handled invalid nick messages. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5194)\n\nJoseph Bisch discovered that Irssi incorrectly handled certain incomplete\ncontrol codes. A remote attacker could use this issue to cause Irssi to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS and Ubuntu 16.10.\n(CVE-2017-5195)\n\nHanno Böck and Joseph Bisch discovered that Irssi incorrectly handled\ncertain incomplete character sequences. A remote attacker could use this\nissue to cause Irssi to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2017-5196)\n\nHanno Böck discovered that Irssi incorrectly handled certain format\nstrings. A remote attacker could use this issue to cause Irssi to crash,\nresulting in a denial of service. (CVE-2017-5356)\n","is_hidden":false,"release_packages":{"precise":[{"name":"irssi","version":"0.8.15-4ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-4ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-4ubuntu3.1"}],"trusty":[{"name":"irssi","version":"0.8.15-5ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"},{"name":"irssi-dev","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"}],"xenial":[{"name":"irssi","version":"0.8.19-1ubuntu1.3","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"},{"name":"irssi-dev","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"}],"yakkety":[{"name":"irssi","version":"0.8.19-1ubuntu2.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2016-7553","CVE-2017-5193","CVE-2017-5194","CVE-2017-5195","CVE-2017-5196","CVE-2017-5356"]}]},{"id":"CVE-2017-5194","published":"2017-01-06T00:00:00","updated_at":"2025-08-25T22:33:37.708044+00:00","description":"\nUse-after-free vulnerability in Irssi before 0.8.21 allows remote attackers\nto cause a denial of service (crash) via an invalid nick message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/05/2","https://irssi.org/security/irssi_sa_2017_01.txt","https://ubuntu.com/security/notices/USN-3184-1","https://www.cve.org/CVERecord?id=CVE-2017-5194"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850403"],"patches":{"irssi":["upstream: https://github.com/irssi/irssi/commit/6c6c42e3d1b49d90aacc0b67f8540471cae02a1d"]},"tags":{},"packages":[{"name":"irssi","source":"https://ubuntu.com/security/cve?package=irssi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi","debian":"https://tracker.debian.org/pkg/irssi","statuses":[{"release_codename":"precise","status":"released","description":"0.8.15-4ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.8.15-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.21-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.19-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.8.19-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3184-1"],"notices":[{"id":"USN-3184-1","title":"Irssi vulnerabilities","summary":"Several security issues were fixed in Irssi.\n","instructions":"After a standard system update you need to restart Irssi to make all the\nnecessary changes.\n","references":[],"published":"2017-02-01T18:08:38.780283","description":"It was discovered that the Irssi buf.pl script set incorrect permissions. A\nlocal attacker could use this issue to retrieve another user's window\ncontents. (CVE-2016-7553)\n\nJoseph Bisch discovered that Irssi incorrectly handled comparing nicks. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5193)\n\nIt was discovered that Irssi incorrectly handled invalid nick messages. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5194)\n\nJoseph Bisch discovered that Irssi incorrectly handled certain incomplete\ncontrol codes. A remote attacker could use this issue to cause Irssi to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS and Ubuntu 16.10.\n(CVE-2017-5195)\n\nHanno Böck and Joseph Bisch discovered that Irssi incorrectly handled\ncertain incomplete character sequences. A remote attacker could use this\nissue to cause Irssi to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2017-5196)\n\nHanno Böck discovered that Irssi incorrectly handled certain format\nstrings. A remote attacker could use this issue to cause Irssi to crash,\nresulting in a denial of service. (CVE-2017-5356)\n","is_hidden":false,"release_packages":{"precise":[{"name":"irssi","version":"0.8.15-4ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-4ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-4ubuntu3.1"}],"trusty":[{"name":"irssi","version":"0.8.15-5ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"},{"name":"irssi-dev","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"}],"xenial":[{"name":"irssi","version":"0.8.19-1ubuntu1.3","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"},{"name":"irssi-dev","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"}],"yakkety":[{"name":"irssi","version":"0.8.19-1ubuntu2.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2016-7553","CVE-2017-5193","CVE-2017-5194","CVE-2017-5195","CVE-2017-5196","CVE-2017-5356"]}]},{"id":"CVE-2017-5193","published":"2017-01-06T00:00:00","updated_at":"2025-08-25T22:33:37.708044+00:00","description":"\nThe nickcmp function in Irssi before 0.8.21 allows remote attackers to\ncause a denial of service (NULL pointer dereference and crash) via a\nmessage without a nick.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/05/2","https://irssi.org/security/irssi_sa_2017_01.txt","https://ubuntu.com/security/notices/USN-3184-1","https://www.cve.org/CVERecord?id=CVE-2017-5193"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850403"],"patches":{"irssi":["upstream: https://github.com/irssi/irssi/commit/6c6c42e3d1b49d90aacc0b67f8540471cae02a1d"]},"tags":{},"packages":[{"name":"irssi","source":"https://ubuntu.com/security/cve?package=irssi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi","debian":"https://tracker.debian.org/pkg/irssi","statuses":[{"release_codename":"precise","status":"released","description":"0.8.15-4ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.8.15-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.21-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.19-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.8.19-1ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3184-1"],"notices":[{"id":"USN-3184-1","title":"Irssi vulnerabilities","summary":"Several security issues were fixed in Irssi.\n","instructions":"After a standard system update you need to restart Irssi to make all the\nnecessary changes.\n","references":[],"published":"2017-02-01T18:08:38.780283","description":"It was discovered that the Irssi buf.pl script set incorrect permissions. A\nlocal attacker could use this issue to retrieve another user's window\ncontents. (CVE-2016-7553)\n\nJoseph Bisch discovered that Irssi incorrectly handled comparing nicks. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5193)\n\nIt was discovered that Irssi incorrectly handled invalid nick messages. A\nremote attacker could use this issue to cause Irssi to crash, resulting in\na denial of service, or possibly execute arbitrary code. (CVE-2017-5194)\n\nJoseph Bisch discovered that Irssi incorrectly handled certain incomplete\ncontrol codes. A remote attacker could use this issue to cause Irssi to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS and Ubuntu 16.10.\n(CVE-2017-5195)\n\nHanno Böck and Joseph Bisch discovered that Irssi incorrectly handled\ncertain incomplete character sequences. A remote attacker could use this\nissue to cause Irssi to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2017-5196)\n\nHanno Böck discovered that Irssi incorrectly handled certain format\nstrings. A remote attacker could use this issue to cause Irssi to crash,\nresulting in a denial of service. (CVE-2017-5356)\n","is_hidden":false,"release_packages":{"precise":[{"name":"irssi","version":"0.8.15-4ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-4ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-4ubuntu3.1"}],"trusty":[{"name":"irssi","version":"0.8.15-5ubuntu3.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"},{"name":"irssi-dev","version":"0.8.15-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.1","pocket":"security"}],"xenial":[{"name":"irssi","version":"0.8.19-1ubuntu1.3","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"},{"name":"irssi-dev","version":"0.8.19-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.3","pocket":"security"}],"yakkety":[{"name":"irssi","version":"0.8.19-1ubuntu2.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2016-7553","CVE-2017-5193","CVE-2017-5194","CVE-2017-5195","CVE-2017-5196","CVE-2017-5356"]}]}],"offset":58920,"limit":20,"total_results":79316}