{"cves":[{"id":"CVE-2016-9179","published":"2016-12-22T21:59:00","updated_at":"2025-08-25T22:13:20.674390+00:00","description":"\nlynx: It was found that Lynx doesn't parse the authority component of the\nURL correctly when the host name part ends with '?', and could instead be\ntricked into connecting to a different host.","ubuntu_description":"\nIt was discovered that Lynx incorrectly handled certain URLs. A remote\nattacker could possibly use this issue to connect to a different host.","notes":[{"author":"ratliff","note":"note that the URL must end in / or the attack won't work"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/03/4","https://www.cve.org/CVERecord?id=CVE-2016-9179","https://ubuntu.com/security/notices/USN-4800-1"],"bugs":[""],"patches":{"lynx-cur":[],"lynx":[]},"tags":{},"packages":[{"name":"lynx","source":"https://ubuntu.com/security/cve?package=lynx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lynx","debian":"https://tracker.debian.org/pkg/lynx","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.8.9dev11-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.8.9dev8-4ubuntu1+esm1","component":null,"pocket":"esm-apps"}]},{"name":"lynx-cur","source":"https://ubuntu.com/security/cve?package=lynx-cur","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lynx-cur","debian":"https://tracker.debian.org/pkg/lynx-cur","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-4800-1"],"notices":[{"id":"USN-4800-1","title":"Lynx vulnerabilities","summary":"Several security issues were fixed in Lynx.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:24:24.708521","description":"It was discovered that Lynx incorrectly handled certain URLs. A remote attacker\ncould possibly use this issue to obtain sensitive information or other\nunspecified impact. This issue only affected Ubuntu 16.04 ESM.\n(CVE-2016-9179)\n\nIt was discovered that Lynx incorrectly handled certain HTML files. A remote\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 16.04 ESM. (CVE-2017-1000211)\n\nThorsten Glaser discovered that Lynx mishandles the userinfo subcomponents of\na URI. An attacker monitoring the network could discover cleartext\ncredentials because they may appear in SNI data. (CVE-2021-38165)","is_hidden":false,"release_packages":{"xenial":[{"name":"lynx","version":"2.8.9dev8-4ubuntu1+esm2","description":"classic non-graphical (text-mode) web browser","is_source":true},{"name":"lynx-cur","version":"2.8.9dev8-4ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx-common","version":"2.8.9dev8-4ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx","version":"2.8.9dev8-4ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"lynx","version":"2.8.9dev16-3ubuntu0.1~esm1","description":"classic non-graphical (text-mode) web browser","is_source":true},{"name":"lynx-common","version":"2.8.9dev16-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx","version":"2.8.9dev16-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"lynx","version":"2.9.0dev.5-1ubuntu0.1~esm1","description":"classic non-graphical (text-mode) web browser","is_source":true},{"name":"lynx-common","version":"2.9.0dev.5-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx","version":"2.9.0dev.5-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-1000211","CVE-2016-9179","CVE-2021-38165"]}]},{"id":"CVE-2016-7091","published":"2016-12-22T21:59:00","updated_at":"2025-08-25T22:09:38.039528+00:00","description":"\nsudo: It was discovered that the default sudo configuration on Red Hat\nEnterprise Linux and possibly other Linux implementations preserves the\nvalue of INPUTRC which could lead to information disclosure. A local user\nwith sudo access to a restricted program that uses readline could use this\nflaw to read content from specially formatted files with elevated\nprivileges provided by sudo.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"INPUTRC isn't included in debian/ubuntu, rh-specific"}],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-7091"],"bugs":[""],"patches":{"sudo":[]},"tags":{},"packages":[{"name":"sudo","source":"https://ubuntu.com/security/cve?package=sudo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sudo","debian":"https://tracker.debian.org/pkg/sudo","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-8743","published":"2016-12-22T00:00:00","updated_at":"2025-08-25T22:12:49.768458+00:00","description":"\nApache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal\nin the whitespace accepted from requests and sent in response lines and\nheaders. Accepting these different behaviors represented a security concern\nwhen httpd participates in any chain of proxies or interacts with back-end\napplication servers, either through mod_proxy or using conventional CGI\nmechanisms, and may result in request smuggling, response splitting and\ncache pollution.","ubuntu_description":"","notes":[{"author":"ratliff","note":"Notes from Debian \"The fix is not fully backwards compatible so\nupstream have created a new option to control this behaviour.\nAffects: 2.2.0 to 2.4.23.\""},{"author":"mdeslaur","note":"This fix no longer allows underscores in host names. Debian\nadded a patch to restore the behaviour:\nhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851357\nhttp://mail-archives.apache.org/mod_mbox/httpd-dev/201702.mbox/%3C20170202125319.GA15948%40redhat.com%3E\n\nThe new configuration option doesn't entirely preserve\nbackwards compatibility:\nhttps://bz.apache.org/bugzilla/show_bug.cgi?id=60783"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.apache.org/thread.html/139862b41c0dfd5e6e00ad89c00119f9faf0dd41a2f927da9c9a4076@%3Cannounce.httpd.apache.org%3E","https://httpd.apache.org/security/vulnerabilities_24.html","https://ubuntu.com/security/notices/USN-3279-1","https://ubuntu.com/security/notices/USN-3373-1","https://www.cve.org/CVERecord?id=CVE-2016-8743"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=847124"],"patches":{"apache2":["upstream: https://svn.apache.org/r1668879","upstream: https://svn.apache.org/r1743516","upstream: https://svn.apache.org/r1773801","upstream: https://svn.apache.org/r1772678","upstream: https://svn.apache.org/r1773802","upstream: https://svn.apache.org/r1773803","upstream: https://svn.apache.org/r1773995","upstream: https://svn.apache.org/r1774429","upstream: https://svn.apache.org/r1778052"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.25-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.18-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.4.25-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.15","component":null,"pocket":"security"}]}],"notices_ids":["USN-3373-1","USN-3279-1"],"notices":[{"id":"USN-3373-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-31T16:07:53.734959","description":"Emmanuel Dreyfus discovered that third-party modules using the\nap_get_basic_auth_pw() function outside of the authentication phase may\nlead to authentication requirements being bypassed. This update adds a new\nap_get_basic_auth_components() function for use by third-party modules.\n(CVE-2017-3167)\n\nVasileios Panopoulos discovered that the Apache mod_ssl module may crash\nwhen third-party modules call ap_hook_process_connection() during an HTTP\nrequest to an HTTPS port. (CVE-2017-3169)\n\nJavier Jiménez discovered that the Apache HTTP Server incorrectly handled\nparsing certain requests. A remote attacker could possibly use this issue\nto cause the Apache HTTP Server to crash, resulting in a denial of service.\n(CVE-2017-7668)\n\nChenQin and Hanno Böck discovered that the Apache mod_mime module\nincorrectly handled certain Content-Type response headers. A remote\nattacker could possibly use this issue to cause the Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2017-7679)\n\nDavid Dennerline and Régis Leroy discovered that the Apache HTTP Server\nincorrectly handled unusual whitespace when parsing requests, contrary to\nspecifications. When being used in combination with a proxy or backend\nserver, a remote attacker could possibly use this issue to perform an\ninjection attack and pollute cache. This update may introduce compatibility\nissues with clients that do not strictly follow HTTP protocol\nspecifications. A new configuration option \"HttpProtocolOptions Unsafe\" can\nbe used to revert to the previous unsafe behaviour in problematic\nenvironments. (CVE-2016-8743)\n","is_hidden":false,"release_packages":{"precise":[{"name":"apache2","version":"2.2.22-1ubuntu1.12","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-bin","version":"2.2.22-1ubuntu1.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.12"}]},"type":"USN","cves_ids":["CVE-2016-8743","CVE-2017-3167","CVE-2017-3169","CVE-2017-7668","CVE-2017-7679"]},{"id":"USN-3279-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-05-09T14:16:57.323404","description":"It was discovered that the Apache mod_session_crypto module was encrypting\ndata and cookies using either CBC or ECB modes. A remote attacker could\npossibly use this issue to perform padding oracle attacks. (CVE-2016-0736)\n\nMaksim Malyutin discovered that the Apache mod_auth_digest module\nincorrectly handled malicious input. A remote attacker could possibly use\nthis issue to cause Apache to crash, resulting in a denial of service.\n(CVE-2016-2161)\n\nDavid Dennerline and Régis Leroy discovered that the Apache HTTP Server\nincorrectly handled unusual whitespace when parsing requests, contrary to\nspecifications. When being used in combination with a proxy or backend\nserver, a remote attacker could possibly use this issue to perform an\ninjection attack and pollute cache. This update may introduce compatibility\nissues with clients that do not strictly follow HTTP protocol\nspecifications. A new configuration option \"HttpProtocolOptions Unsafe\" can\nbe used to revert to the previous unsafe behaviour in problematic\nenvironments. (CVE-2016-8743)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.2","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"}],"yakkety":[{"name":"apache2","version":"2.4.18-2ubuntu4.1","description":"Apache HTTP server","is_source":true},{"name":"apache2-bin","version":"2.4.18-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2016-0736","CVE-2016-2161","CVE-2016-8743"]}]},{"id":"CVE-2016-2161","published":"2016-12-22T00:00:00","updated_at":"2025-08-25T21:56:45.916153+00:00","description":"\nIn Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to\nmod_auth_digest can cause the server to crash, and each instance continues\nto crash even for subsequently valid requests.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.apache.org/thread.html/139862b41c0dfd5e6e00ad89c00119f9faf0dd41a2f927da9c9a4076@%3Cannounce.httpd.apache.org%3E","https://httpd.apache.org/security/vulnerabilities_24.html","https://ubuntu.com/security/notices/USN-3279-1","https://www.cve.org/CVERecord?id=CVE-2016-2161"],"bugs":[""],"patches":{"apache2":["upstream: https://svn.apache.org/viewvc?view=revision&revision=1772919","upstream: https://svn.apache.org/viewvc?view=revision&revision=1773069"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"precise","status":"not-affected","description":"2.2.22-1ubuntu1.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.15","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.25-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.18-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.4.25-3ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3279-1"],"notices":[{"id":"USN-3279-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-05-09T14:16:57.323404","description":"It was discovered that the Apache mod_session_crypto module was encrypting\ndata and cookies using either CBC or ECB modes. A remote attacker could\npossibly use this issue to perform padding oracle attacks. (CVE-2016-0736)\n\nMaksim Malyutin discovered that the Apache mod_auth_digest module\nincorrectly handled malicious input. A remote attacker could possibly use\nthis issue to cause Apache to crash, resulting in a denial of service.\n(CVE-2016-2161)\n\nDavid Dennerline and Régis Leroy discovered that the Apache HTTP Server\nincorrectly handled unusual whitespace when parsing requests, contrary to\nspecifications. When being used in combination with a proxy or backend\nserver, a remote attacker could possibly use this issue to perform an\ninjection attack and pollute cache. This update may introduce compatibility\nissues with clients that do not strictly follow HTTP protocol\nspecifications. A new configuration option \"HttpProtocolOptions Unsafe\" can\nbe used to revert to the previous unsafe behaviour in problematic\nenvironments. (CVE-2016-8743)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.2","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"}],"yakkety":[{"name":"apache2","version":"2.4.18-2ubuntu4.1","description":"Apache HTTP server","is_source":true},{"name":"apache2-bin","version":"2.4.18-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2016-0736","CVE-2016-2161","CVE-2016-8743"]}]},{"id":"CVE-2016-0736","published":"2016-12-22T00:00:00","updated_at":"2025-08-25T21:50:49.597983+00:00","description":"\nIn Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was\nencrypting its data/cookie using the configured ciphers with possibly\neither CBC or ECB modes of operation (AES256-CBC by default), hence no\nselectable or builtin authenticated encryption. This made it vulnerable to\npadding oracle attacks, particularly with CBC.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.apache.org/thread.html/139862b41c0dfd5e6e00ad89c00119f9faf0dd41a2f927da9c9a4076@%3Cannounce.httpd.apache.org%3E","https://httpd.apache.org/security/vulnerabilities_24.html","https://ubuntu.com/security/notices/USN-3279-1","https://www.cve.org/CVERecord?id=CVE-2016-0736"],"bugs":[""],"patches":{"apache2":["upstream: https://svn.apache.org/viewvc?view=revision&revision=1772812","upstream: https://svn.apache.org/viewvc?view=revision&revision=1772925"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"precise","status":"not-affected","description":"2.2.22-1ubuntu1.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.15","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.25-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.4.18-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.4.25-3ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3279-1"],"notices":[{"id":"USN-3279-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-05-09T14:16:57.323404","description":"It was discovered that the Apache mod_session_crypto module was encrypting\ndata and cookies using either CBC or ECB modes. A remote attacker could\npossibly use this issue to perform padding oracle attacks. (CVE-2016-0736)\n\nMaksim Malyutin discovered that the Apache mod_auth_digest module\nincorrectly handled malicious input. A remote attacker could possibly use\nthis issue to cause Apache to crash, resulting in a denial of service.\n(CVE-2016-2161)\n\nDavid Dennerline and Régis Leroy discovered that the Apache HTTP Server\nincorrectly handled unusual whitespace when parsing requests, contrary to\nspecifications. When being used in combination with a proxy or backend\nserver, a remote attacker could possibly use this issue to perform an\ninjection attack and pollute cache. This update may introduce compatibility\nissues with clients that do not strictly follow HTTP protocol\nspecifications. A new configuration option \"HttpProtocolOptions Unsafe\" can\nbe used to revert to the previous unsafe behaviour in problematic\nenvironments. (CVE-2016-8743)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.15","pocket":"security"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.2","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.2","pocket":"security"}],"yakkety":[{"name":"apache2","version":"2.4.18-2ubuntu4.1","description":"Apache HTTP server","is_source":true},{"name":"apache2-bin","version":"2.4.18-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2016-0736","CVE-2016-2161","CVE-2016-8743"]}]},{"id":"CVE-2016-5103","published":"2016-12-21T16:59:00","updated_at":"2025-08-04T19:24:34.503169+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2016-4552. Reason: This candidate is a reservation duplicate of\nCVE-2016-4552. Notes: All CVE users should reference CVE-2016-4552 instead\nof this candidate. All references and descriptions in this candidate have\nbeen removed to prevent accidental usage","ubuntu_description":"","notes":[{"author":"sbeattie","note":"rejected, duplicate of CVE-2016-4552."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/05/25/8","https://www.cve.org/CVERecord?id=CVE-2016-5103"],"bugs":["https://github.com/roundcube/roundcubemail/issues/5240"],"patches":{"roundcube":["upstream: https://github.com/roundcube/roundcubemail/pull/5241"]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"precise","status":"not-affected","description":"REJECT","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.0+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"REJECT","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"REJECT","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"REJECT","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [REJECT]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9586","published":"2016-12-21T00:00:00","updated_at":"2025-08-25T22:14:23.821229+00:00","description":"\ncurl before version 7.52.0 is vulnerable to a buffer overflow when doing a\nlarge floating point output in libcurl's implementation of the printf()\nfunctions. If there are any application that accepts a format string from\nthe outside without necessary input filtering, it could allow remote\nattacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://curl.haxx.se/docs/adv_20161221A.html","https://ubuntu.com/security/notices/USN-3441-1","https://ubuntu.com/security/notices/USN-3441-2","https://www.cve.org/CVERecord?id=CVE-2016-9586"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848958"],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/3ab3c16db6a5674f53cf23d56512a405fde0b2c9","upstream: https://curl.haxx.se/CVE-2016-9586.patch"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.52.0","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"7.52.1-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.35.0-1ubuntu2.11","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.47.0-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.52.1-4ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3441-1","USN-3441-2"],"notices":[{"id":"USN-3441-1","title":"curl vulnerabilities","summary":"Several security issues were fixed in curl.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-10-10T12:54:33.773269","description":"Daniel Stenberg discovered that curl incorrectly handled large floating\npoint output. A remote attacker could use this issue to cause curl to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-9586)\n\nEven Rouault discovered that curl incorrectly handled large file names when\ndoing TFTP transfers. A remote attacker could use this issue to cause curl\nto crash, resulting in a denial of service, or possibly obtain sensitive\nmemory contents. (CVE-2017-1000100)\n\nBrian Carpenter and Yongji Ouyang discovered that curl incorrectly handled\nnumerical range globbing. A remote attacker could use this issue to cause\ncurl to crash, resulting in a denial of service, or possibly obtain\nsensitive memory contents. (CVE-2017-1000101)\n\nMax Dymond discovered that curl incorrectly handled FTP PWD responses. A\nremote attacker could use this issue to cause curl to crash, resulting in a\ndenial of service. (CVE-2017-1000254)\n\nBrian Carpenter discovered that curl incorrectly handled the --write-out\ncommand line option. A local attacker could possibly use this issue to\nobtain sensitive memory contents. (CVE-2017-7407)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"curl","version":"7.35.0-1ubuntu2.11","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"curl-udeb","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl3","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl3-nss","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl3-udeb","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl4-doc","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.35.0-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.11","pocket":"security"}],"xenial":[{"name":"curl","version":"7.47.0-1ubuntu2.3","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl3","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl3-gnutls","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl3-nss","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-doc","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-gnutls-dev","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-nss-dev","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"},{"name":"libcurl4-openssl-dev","version":"7.47.0-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.3","pocket":"security"}],"zesty":[{"name":"curl","version":"7.52.1-4ubuntu1.2","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"curl","version":"7.52.1-4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.52.1-4ubuntu1.2"},{"name":"libcurl3","version":"7.52.1-4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.52.1-4ubuntu1.2"},{"name":"libcurl3-gnutls","version":"7.52.1-4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.52.1-4ubuntu1.2"},{"name":"libcurl3-nss","version":"7.52.1-4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.52.1-4ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2016-9586","CVE-2017-1000100","CVE-2017-1000101","CVE-2017-1000254","CVE-2017-7407"]},{"id":"USN-3441-2","title":"curl vulnerabilities","summary":"Several security issues were fixed in curl.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-10-23T19:47:39.131938","description":"USN-3441-1 fixed several vulnerabilities in curl. This update\nprovides the corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n Daniel Stenberg discovered that curl incorrectly handled large floating\n point output. A remote attacker could use this issue to cause curl to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code. (CVE-2016-9586)\n\n Even Rouault discovered that curl incorrectly handled large file names when\n doing TFTP transfers. A remote attacker could use this issue to cause curl\n to crash, resulting in a denial of service, or possibly obtain sensitive\n memory contents. (CVE-2017-1000100)\n\n Brian Carpenter and Yongji Ouyang discovered that curl incorrectly handled\n numerical range globbing. A remote attacker could use this issue to cause\n curl to crash, resulting in a denial of service, or possibly obtain\n sensitive memory contents. (CVE-2017-1000101)\n\n Max Dymond discovered that curl incorrectly handled FTP PWD responses. A\n remote attacker could use this issue to cause curl to crash, resulting in a\n denial of service. (CVE-2017-1000254)\n\n Brian Carpenter discovered that curl incorrectly handled IMAP FETCH\n response lines. A remote attacker could use this issue to cause curl to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.(CVE-2017-1000257)\n\n Brian Carpenter discovered that curl incorrectly handled the --write-out\n command line option. A local attacker could possibly use this issue to\n obtain sensitive memory contents. (CVE-2017-7407)\n","is_hidden":false,"release_packages":{"precise":[{"name":"curl","version":"7.22.0-3ubuntu4.18","description":"HTTP, HTTPS, and FTP client and client libraries","is_source":true},{"name":"libcurl3-nss","version":"7.22.0-3ubuntu4.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.22.0-3ubuntu4.18"},{"name":"curl","version":"7.22.0-3ubuntu4.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.22.0-3ubuntu4.18"},{"name":"libcurl3-gnutls","version":"7.22.0-3ubuntu4.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.22.0-3ubuntu4.18"},{"name":"libcurl3","version":"7.22.0-3ubuntu4.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/curl","version_link":"https://launchpad.net/ubuntu/+source/curl/7.22.0-3ubuntu4.18"}]},"type":"USN","cves_ids":["CVE-2016-9586","CVE-2017-1000100","CVE-2017-1000254","CVE-2017-1000257","CVE-2017-7407"]}]},{"id":"CVE-2016-5303","published":"2016-12-20T22:59:00","updated_at":"2025-08-26T11:55:13.683398+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Horde Text Filter API in\nHorde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows\nremote attackers to inject arbitrary web script or HTML via crafted\ndata:text/html content in a form (1) action or (2) xlink attribute.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://marc.info/?l=horde-announce&m=147319066126665&w=2","http://marc.info/?l=horde-announce&m=147319089526753&w=2","https://github.com/horde/horde/commit/30d5506c20d26efbb9942fbdc6f981a0bd333b97","https://github.com/horde/horde/commit/4d8176d1e9ef5cbd2b3fcacd9b9a4c8e482fb424","https://www.cve.org/CVERecord?id=CVE-2016-5303"],"bugs":[""],"patches":{"php-horde-text-filter":[]},"tags":{},"packages":[{"name":"php-horde-text-filter","source":"https://ubuntu.com/security/cve?package=php-horde-text-filter","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-horde-text-filter","debian":"https://tracker.debian.org/pkg/php-horde-text-filter","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4552","published":"2016-12-20T22:59:00","updated_at":"2025-08-25T22:03:39.867692+00:00","description":"\nCross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.2.0\nallows remote attackers to inject arbitrary web script or HTML via the href\nattribute in an area tag in an e-mail message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/roundcube/roundcubemail/issues/5240","https://github.com/roundcube/roundcubemail/wiki/Changelog#release-120","https://www.cve.org/CVERecord?id=CVE-2016-4552"],"bugs":[""],"patches":{"roundcube":[]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.2.0+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.6+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.0+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.2.0+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.2.0+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1255","published":"2016-12-20T00:00:00","updated_at":"2025-08-25T21:54:02.796315+00:00","description":"\nThe pg_ctlcluster script in postgresql-common package in Debian wheezy\nbefore 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable\nbefore 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS\nbefore 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu\n17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows\nlocal users to gain root privileges via a symlink attack on a logfile in\n/var/log/postgresql.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/log/","https://ubuntu.com/security/notices/USN-3476-1","https://ubuntu.com/security/notices/USN-3476-2","https://www.cve.org/CVERecord?id=CVE-2016-1255"],"bugs":[""],"patches":{"postgresql-common":["upstream: https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=c8989206ec360f19"]},"tags":{},"packages":[{"name":"postgresql-common","source":"https://ubuntu.com/security/cve?package=postgresql-common","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-common","debian":"https://tracker.debian.org/pkg/postgresql-common","statuses":[{"release_codename":"artful","status":"not-affected","description":"184ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"154ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"178","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"173ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"179","component":null,"pocket":"security"}]}],"notices_ids":["USN-3476-2","USN-3476-1"],"notices":[{"id":"USN-3476-2","title":"postgresql-common vulnerabilities","summary":"postgresql-common could be made to overwrite files as the administrator.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-11-27T18:31:33.795743","description":"USN-3476-1 fixed two vulnerabilities in postgresql-common. This update provides\nthe corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n Dawid Golunski discovered that the postgresql-common pg_ctlcluster script\n incorrectly handled symlinks. A local attacker could possibly use this\n issue to escalate privileges. (CVE-2016-1255)\n\n It was discovered that the postgresql-common helper scripts incorrectly\n handled symlinks. A local attacker could possibly use this issue to\n escalate privileges. (CVE-2017-8806)\n","is_hidden":false,"release_packages":{"precise":[{"name":"postgresql-common","version":"129ubuntu1.2","description":"PostgreSQL database-cluster manager","is_source":true},{"name":"postgresql-common","version":"129ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/129ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2016-1255","CVE-2017-8806"]},{"id":"USN-3476-1","title":"postgresql-common vulnerabilities","summary":"postgresql-common could be made to overwrite files as the administrator.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-11-09T19:28:04.754906","description":"Dawid Golunski discovered that the postgresql-common pg_ctlcluster script\nincorrectly handled symlinks. A local attacker could possibly use this\nissue to escalate privileges. This issue only affected Ubuntu 14.04 LTS and\nUbuntu 16.04 LTS. (CVE-2016-1255)\n\nIt was discovered that the postgresql-common helper scripts incorrectly\nhandled symlinks. A local attacker could possibly use this issue to\nescalate privileges. (CVE-2017-8806)\n","is_hidden":false,"release_packages":{"artful":[{"name":"postgresql-common","version":"184ubuntu1.1","description":"PostgreSQL database-cluster manager","is_source":true},{"name":"postgresql-common","version":"184ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/184ubuntu1.1"}],"trusty":[{"name":"postgresql-common","version":"154ubuntu1.1","description":"PostgreSQL database-cluster manager","is_source":true},{"name":"postgresql","version":"9.3+154ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/154ubuntu1.1","pocket":"security"},{"name":"postgresql-client","version":"9.3+154ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/154ubuntu1.1","pocket":"security"},{"name":"postgresql-client-common","version":"154ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/154ubuntu1.1","pocket":"security"},{"name":"postgresql-common","version":"154ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/154ubuntu1.1","pocket":"security"},{"name":"postgresql-contrib","version":"9.3+154ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/154ubuntu1.1","pocket":"security"},{"name":"postgresql-doc","version":"9.3+154ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/154ubuntu1.1","pocket":"security"},{"name":"postgresql-server-dev-all","version":"154ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/154ubuntu1.1","pocket":"security"}],"xenial":[{"name":"postgresql-common","version":"173ubuntu0.1","description":"PostgreSQL database-cluster manager","is_source":true},{"name":"postgresql","version":"9.5+173ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/173ubuntu0.1","pocket":"security"},{"name":"postgresql-client","version":"9.5+173ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/173ubuntu0.1","pocket":"security"},{"name":"postgresql-client-common","version":"173ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/173ubuntu0.1","pocket":"security"},{"name":"postgresql-common","version":"173ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/173ubuntu0.1","pocket":"security"},{"name":"postgresql-contrib","version":"9.5+173ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/173ubuntu0.1","pocket":"security"},{"name":"postgresql-doc","version":"9.5+173ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/173ubuntu0.1","pocket":"security"},{"name":"postgresql-server-dev-all","version":"173ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/173ubuntu0.1","pocket":"security"}],"zesty":[{"name":"postgresql-common","version":"179ubuntu0.1","description":"PostgreSQL database-cluster manager","is_source":true},{"name":"postgresql-common","version":"179ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-common","version_link":"https://launchpad.net/ubuntu/+source/postgresql-common/179ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2016-1255","CVE-2017-8806"]}]},{"id":"CVE-2016-2126","published":"2016-12-19T00:00:00","updated_at":"2025-08-25T21:56:41.250850+00:00","description":"\nSamba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to\nincorrect handling of the PAC (Privilege Attribute Certificate) checksum. A\nremote, authenticated, attacker can cause the winbindd process to crash\nusing a legitimate Kerberos ticket. A local service with access to the\nwinbindd privileged pipe can cause winbindd to cache elevated access\npermissions.","ubuntu_description":"\nVolker Lendecke discovered that Kerberos PAC validation implementation\nin Samba contained multiple vulnerabilities. An authenticated attacker\ncould use this to cause a denial of service or gain administrative\nprivileges.","notes":[{"author":"mdeslaur","note":"4.0.0+"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.samba.org/samba/security/CVE-2016-2126.html","https://ubuntu.com/security/notices/USN-3158-1","https://www.cve.org/CVERecord?id=CVE-2016-2126"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=12446"],"patches":{"samba":[],"samba4":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.14.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.16.04.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:4.4.5+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:4.4.5+dfsg-2ubuntu7","component":null,"pocket":"security"}]},{"name":"samba4","source":"https://ubuntu.com/security/cve?package=samba4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba4","debian":"https://tracker.debian.org/pkg/samba4","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3158-1"],"notices":[{"id":"USN-3158-1","title":"Samba vulnerabilities","summary":"Several security issues were fixed in Samba.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-12-19T17:34:58.822245","description":"Frederic Besler and others discovered that the ndr_pull_dnsp_nam\nfunction in Samba contained an integer overflow. An authenticated\nattacker could use this to gain administrative privileges. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10.\n(CVE-2016-2123)\n\nSimo Sorce discovered that that Samba clients always requested\na forwardable ticket when using Kerberos authentication. An\nattacker could use this to impersonate an authenticated user or\nservice. (CVE-2016-2125)\n\nVolker Lendecke discovered that Kerberos PAC validation implementation\nin Samba contained multiple vulnerabilities. An authenticated attacker\ncould use this to cause a denial of service or gain administrative\nprivileges. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04\nLTS, and Ubuntu 16.10. (CVE-2016-2126)\n","is_hidden":false,"release_packages":{"precise":[{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.5","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libsmbclient","version":"2:3.6.25-0ubuntu0.12.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.5"},{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.5"}],"trusty":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libpam-smbpass","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbsharemodes-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbsharemodes0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-doc","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"}],"xenial":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"ctdb","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"}],"yakkety":[{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.2","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libsmbclient","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"},{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"},{"name":"winbind","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"}]},"type":"USN","cves_ids":["CVE-2016-2123","CVE-2016-2125","CVE-2016-2126"]}]},{"id":"CVE-2016-2125","published":"2016-12-19T00:00:00","updated_at":"2025-08-25T21:56:41.250850+00:00","description":"\nIt was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always\nrequested forwardable tickets when using Kerberos authentication. A service\nto which Samba authenticated using Kerberos could subsequently use the\nticket to impersonate Samba to other services or domain users.","ubuntu_description":"\nSimo Sorce discovered that that Samba clients always requested\na forwardable ticket when using Kerberos authentication. An\nattacker could use this to impersonate an authenticated user or\nservice.","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.samba.org/samba/security/CVE-2016-2125.html","https://ubuntu.com/security/notices/USN-3158-1","https://www.cve.org/CVERecord?id=CVE-2016-2125"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=12445"],"patches":{"samba":[],"samba4":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"precise","status":"released","description":"2:3.6.25-0ubuntu0.12.04.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.14.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.16.04.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:4.4.5+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:4.4.5+dfsg-2ubuntu7","component":null,"pocket":"security"}]},{"name":"samba4","source":"https://ubuntu.com/security/cve?package=samba4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba4","debian":"https://tracker.debian.org/pkg/samba4","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3158-1"],"notices":[{"id":"USN-3158-1","title":"Samba vulnerabilities","summary":"Several security issues were fixed in Samba.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-12-19T17:34:58.822245","description":"Frederic Besler and others discovered that the ndr_pull_dnsp_nam\nfunction in Samba contained an integer overflow. An authenticated\nattacker could use this to gain administrative privileges. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10.\n(CVE-2016-2123)\n\nSimo Sorce discovered that that Samba clients always requested\na forwardable ticket when using Kerberos authentication. An\nattacker could use this to impersonate an authenticated user or\nservice. (CVE-2016-2125)\n\nVolker Lendecke discovered that Kerberos PAC validation implementation\nin Samba contained multiple vulnerabilities. An authenticated attacker\ncould use this to cause a denial of service or gain administrative\nprivileges. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04\nLTS, and Ubuntu 16.10. (CVE-2016-2126)\n","is_hidden":false,"release_packages":{"precise":[{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.5","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libsmbclient","version":"2:3.6.25-0ubuntu0.12.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.5"},{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.5"}],"trusty":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libpam-smbpass","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbsharemodes-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbsharemodes0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-doc","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"}],"xenial":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"ctdb","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"}],"yakkety":[{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.2","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libsmbclient","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"},{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"},{"name":"winbind","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"}]},"type":"USN","cves_ids":["CVE-2016-2123","CVE-2016-2125","CVE-2016-2126"]}]},{"id":"CVE-2016-2123","published":"2016-12-19T00:00:00","updated_at":"2025-08-25T21:56:36.855586+00:00","description":"\nA flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine\nndr_pull_dnsp_name contains an integer wrap problem, leading to an\nattacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from\nthe Samba Active Directory ldb database. Any user who can write to the\ndnsRecord attribute over LDAP can trigger this memory corruption. By\ndefault, all authenticated LDAP users can write to the dnsRecord attribute\non new DNS objects. This makes the defect a remote privilege escalation.","ubuntu_description":"\nFrederic Besler and others discovered that the routine\nndr_pull_dnsp_nam in Samba contained an integer overflow. An\nauthenticated attacker could use this to gain administrative\nprivileges.","notes":[{"author":"mdeslaur","note":"4.0.0+ only"}],"codename":null,"priority":"high","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.samba.org/samba/security/CVE-2016-2123.html","https://ubuntu.com/security/notices/USN-3158-1","https://www.cve.org/CVERecord?id=CVE-2016-2123"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=12409"],"patches":{"samba":[],"samba4":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"trusty","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.14.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.16.04.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:4.4.5+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:4.4.5+dfsg-2ubuntu7","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"samba4","source":"https://ubuntu.com/security/cve?package=samba4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba4","debian":"https://tracker.debian.org/pkg/samba4","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3158-1"],"notices":[{"id":"USN-3158-1","title":"Samba vulnerabilities","summary":"Several security issues were fixed in Samba.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-12-19T17:34:58.822245","description":"Frederic Besler and others discovered that the ndr_pull_dnsp_nam\nfunction in Samba contained an integer overflow. An authenticated\nattacker could use this to gain administrative privileges. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10.\n(CVE-2016-2123)\n\nSimo Sorce discovered that that Samba clients always requested\na forwardable ticket when using Kerberos authentication. An\nattacker could use this to impersonate an authenticated user or\nservice. (CVE-2016-2125)\n\nVolker Lendecke discovered that Kerberos PAC validation implementation\nin Samba contained multiple vulnerabilities. An authenticated attacker\ncould use this to cause a denial of service or gain administrative\nprivileges. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04\nLTS, and Ubuntu 16.10. (CVE-2016-2126)\n","is_hidden":false,"release_packages":{"precise":[{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.5","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libsmbclient","version":"2:3.6.25-0ubuntu0.12.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.5"},{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.5"}],"trusty":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libpam-smbpass","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbsharemodes-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libsmbsharemodes0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-doc","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.4","pocket":"security"}],"xenial":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"ctdb","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.3","pocket":"security"}],"yakkety":[{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.2","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libsmbclient","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"},{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"},{"name":"winbind","version":"2:4.4.5+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.2"}]},"type":"USN","cves_ids":["CVE-2016-2123","CVE-2016-2125","CVE-2016-2126"]}]},{"id":"CVE-2016-5193","published":"2016-12-18T03:59:00","updated_at":"2025-08-25T22:05:28.328703+00:00","description":"\nGoogle Chrome prior to 54.0 for iOS had insufficient validation of URLs for\nwindows open by DOM, which allowed a remote attacker to bypass restrictions\non navigation to certain URL schemes via crafted HTML pages.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Looks like it's iOS only"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5193"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5191","published":"2016-12-18T03:59:00","updated_at":"2025-08-25T22:05:22.734942+00:00","description":"\nBookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac,\nand Linux; 54.0.2840.85 for Android had insufficient validation of supplied\ndata, which allowed a remote attacker to inject arbitrary scripts or HTML\n(UXSS) via crafted HTML pages, as demonstrated by an interpretation\nconflict between userinfo and scheme in an\nhttp://javascript:payload@example.com URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5191"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"58.0.3029.81-0ubuntu0.14.04.1172","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"54.0.2840.59","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"55.0.2883.87-0ubuntu0.16.04.1263","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"55.0.2883.87-0ubuntu0.16.10.1328","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"55.0.2883.87-0ubuntu1","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5190","published":"2016-12-18T03:59:00","updated_at":"2025-08-25T22:05:22.734942+00:00","description":"\nGoogle Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux;\n54.0.2840.85 for Android incorrectly handled object lifecycles during\nshutdown, which allowed a remote attacker to perform an out of bounds\nmemory read via crafted HTML pages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5190"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"58.0.3029.81-0ubuntu0.14.04.1172","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"54.0.2840.59","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"55.0.2883.87-0ubuntu0.16.04.1263","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"55.0.2883.87-0ubuntu0.16.10.1328","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"55.0.2883.87-0ubuntu1","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5184","published":"2016-12-18T03:59:00","updated_at":"2025-08-25T22:05:22.734942+00:00","description":"\nPDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux;\n54.0.2840.85 for Android incorrectly handled object lifecycles in\nCFFL_FormFillter::KillFocusForAnnot, which allowed a remote attacker to\npotentially exploit heap corruption via crafted PDF files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5184"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"58.0.3029.81-0ubuntu0.14.04.1172","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"54.0.2840.59","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"55.0.2883.87-0ubuntu0.16.04.1263","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"55.0.2883.87-0ubuntu0.16.10.1328","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"55.0.2883.87-0ubuntu1","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5183","published":"2016-12-18T03:59:00","updated_at":"2025-08-25T22:05:22.734942+00:00","description":"\nA heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for\nWindows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker\nto potentially exploit heap corruption via crafted PDF files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5183"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"58.0.3029.81-0ubuntu0.14.04.1172","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"54.0.2840.59","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"55.0.2883.87-0ubuntu0.16.04.1263","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"55.0.2883.87-0ubuntu0.16.10.1328","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"55.0.2883.87-0ubuntu1","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9998","published":"2016-12-17T03:59:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nSPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in\n/ecrire/exec/info_plugin.php involving the `$plugin` parameter, as\ndemonstrated by a /ecrire/?exec=info_plugin URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://core.spip.net/projects/spip/repository/revisions/23288","https://www.cve.org/CVERecord?id=CVE-2016-9998"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848641"],"patches":{"spip":[]},"tags":{},"packages":[{"name":"spip","source":"https://ubuntu.com/security/cve?package=spip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spip","debian":"https://tracker.debian.org/pkg/spip","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9997","published":"2016-12-17T03:59:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nSPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in\n/ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated\nby a /ecrire/?exec=puce_statut URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://core.spip.net/projects/spip/repository/revisions/23288","https://www.cve.org/CVERecord?id=CVE-2016-9997"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848641"],"patches":{"spip":[]},"tags":{},"packages":[{"name":"spip","source":"https://ubuntu.com/security/cve?package=spip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=spip","debian":"https://tracker.debian.org/pkg/spip","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.1.4-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":59080,"limit":20,"total_results":79316}