{"cves":[{"id":"CVE-2016-4563","published":"2016-06-04T00:00:00","updated_at":"2025-08-25T22:03:44.682356+00:00","description":"\nThe TraceStrokePolygon function in MagickCore/draw.c in ImageMagick before\n6.9.4-0 and 7.x before 7.0.1-2 mishandles the relationship between the\nBezierQuantum value and certain strokes data, which allows remote attackers\nto cause a denial of service (buffer overflow and application crash) or\npossibly have unspecified other impact via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0122-Prevent-buffer-overflow-in-magick-draw.c.patch"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.imagemagick.org/script/changelog.php","https://ubuntu.com/security/notices/USN-3131-1","https://www.cve.org/CVERecord?id=CVE-2016-4563"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1615929"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/726812fa2fa7ce16bcf58f6e115f65427a1c0950"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-5+deb8u4","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3131-1"],"notices":[{"id":"USN-3131-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-11-21T14:07:40.268837","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2014-8354","CVE-2014-8355","CVE-2014-8562","CVE-2014-8716","CVE-2014-9805","CVE-2014-9806","CVE-2014-9807","CVE-2014-9808","CVE-2014-9809","CVE-2014-9810","CVE-2014-9811","CVE-2014-9812","CVE-2014-9813","CVE-2014-9814","CVE-2014-9815","CVE-2014-9816","CVE-2014-9817","CVE-2014-9818","CVE-2014-9819","CVE-2014-9820","CVE-2014-9821","CVE-2014-9822","CVE-2014-9823","CVE-2014-9826","CVE-2014-9828","CVE-2014-9829","CVE-2014-9830","CVE-2014-9831","CVE-2014-9833","CVE-2014-9834","CVE-2014-9835","CVE-2014-9836","CVE-2014-9837","CVE-2014-9838","CVE-2014-9839","CVE-2014-9840","CVE-2014-9841","CVE-2014-9843","CVE-2014-9844","CVE-2014-9845","CVE-2014-9846","CVE-2014-9847","CVE-2014-9848","CVE-2014-9849","CVE-2014-9850","CVE-2014-9851","CVE-2014-9853","CVE-2014-9854","CVE-2014-9907","CVE-2015-8894","CVE-2015-8895","CVE-2015-8896","CVE-2015-8897","CVE-2015-8898","CVE-2015-8900","CVE-2015-8901","CVE-2015-8902","CVE-2015-8903","CVE-2015-8957","CVE-2015-8958","CVE-2015-8959","CVE-2016-4562","CVE-2016-4563","CVE-2016-4564","CVE-2016-5010","CVE-2016-5687","CVE-2016-5688","CVE-2016-5689","CVE-2016-5690","CVE-2016-5691","CVE-2016-5841","CVE-2016-5842","CVE-2016-6491","CVE-2016-6823","CVE-2016-7101","CVE-2016-7513","CVE-2016-7514","CVE-2016-7515","CVE-2016-7516","CVE-2016-7517","CVE-2016-7518","CVE-2016-7519","CVE-2016-7520","CVE-2016-7521","CVE-2016-7522","CVE-2016-7523","CVE-2016-7524","CVE-2016-7525","CVE-2016-7526","CVE-2016-7527","CVE-2016-7528","CVE-2016-7529","CVE-2016-7530","CVE-2016-7531","CVE-2016-7532","CVE-2016-7533","CVE-2016-7534","CVE-2016-7535","CVE-2016-7536","CVE-2016-7537","CVE-2016-7538","CVE-2016-7539","CVE-2016-7540"]}]},{"id":"CVE-2016-4562","published":"2016-06-04T00:00:00","updated_at":"2025-08-25T22:03:44.682356+00:00","description":"\nThe DrawDashPolygon function in MagickCore/draw.c in ImageMagick before\n6.9.4-0 and 7.x before 7.0.1-2 mishandles calculations of certain vertices\ninteger data, which allows remote attackers to cause a denial of service\n(buffer overflow and application crash) or possibly have unspecified other\nimpact via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0122-Prevent-buffer-overflow-in-magick-draw.c.patch"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.imagemagick.org/script/changelog.php","https://ubuntu.com/security/notices/USN-3131-1","https://www.cve.org/CVERecord?id=CVE-2016-4562"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832885","https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1615929"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/726812fa2fa7ce16bcf58f6e115f65427a1c0950"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-5+deb8u4","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3131-1"],"notices":[{"id":"USN-3131-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-11-21T14:07:40.268837","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"},{"name":"libmagickcore4-extra","version":"8:6.6.9.7-5ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.5"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.2","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.2","pocket":"security"}],"yakkety":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2014-8354","CVE-2014-8355","CVE-2014-8562","CVE-2014-8716","CVE-2014-9805","CVE-2014-9806","CVE-2014-9807","CVE-2014-9808","CVE-2014-9809","CVE-2014-9810","CVE-2014-9811","CVE-2014-9812","CVE-2014-9813","CVE-2014-9814","CVE-2014-9815","CVE-2014-9816","CVE-2014-9817","CVE-2014-9818","CVE-2014-9819","CVE-2014-9820","CVE-2014-9821","CVE-2014-9822","CVE-2014-9823","CVE-2014-9826","CVE-2014-9828","CVE-2014-9829","CVE-2014-9830","CVE-2014-9831","CVE-2014-9833","CVE-2014-9834","CVE-2014-9835","CVE-2014-9836","CVE-2014-9837","CVE-2014-9838","CVE-2014-9839","CVE-2014-9840","CVE-2014-9841","CVE-2014-9843","CVE-2014-9844","CVE-2014-9845","CVE-2014-9846","CVE-2014-9847","CVE-2014-9848","CVE-2014-9849","CVE-2014-9850","CVE-2014-9851","CVE-2014-9853","CVE-2014-9854","CVE-2014-9907","CVE-2015-8894","CVE-2015-8895","CVE-2015-8896","CVE-2015-8897","CVE-2015-8898","CVE-2015-8900","CVE-2015-8901","CVE-2015-8902","CVE-2015-8903","CVE-2015-8957","CVE-2015-8958","CVE-2015-8959","CVE-2016-4562","CVE-2016-4563","CVE-2016-4564","CVE-2016-5010","CVE-2016-5687","CVE-2016-5688","CVE-2016-5689","CVE-2016-5690","CVE-2016-5691","CVE-2016-5841","CVE-2016-5842","CVE-2016-6491","CVE-2016-6823","CVE-2016-7101","CVE-2016-7513","CVE-2016-7514","CVE-2016-7515","CVE-2016-7516","CVE-2016-7517","CVE-2016-7518","CVE-2016-7519","CVE-2016-7520","CVE-2016-7521","CVE-2016-7522","CVE-2016-7523","CVE-2016-7524","CVE-2016-7525","CVE-2016-7526","CVE-2016-7527","CVE-2016-7528","CVE-2016-7529","CVE-2016-7530","CVE-2016-7531","CVE-2016-7532","CVE-2016-7533","CVE-2016-7534","CVE-2016-7535","CVE-2016-7536","CVE-2016-7537","CVE-2016-7538","CVE-2016-7539","CVE-2016-7540"]}]},{"id":"CVE-2016-3096","published":"2016-06-03T14:59:00","updated_at":"2025-08-25T21:59:17.297351+00:00","description":"\nThe create_script function in the lxc_container module in Ansible before\n1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary\nfiles or gain privileges via a symlink attack on (1)\n/opt/.lxc-attach-script, (2) the archived container in the archive_path\ndirectory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err\nfiles in the temporary directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1322925","https://sources.debian.net/src/ansible/2.0.1.0-1/lib/ansible/modules/extras/cloud/lxc/lxc_container.py/?hl=523#L523","https://www.cve.org/CVERecord?id=CVE-2016-3096"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=819676"],"patches":{"ansible":["upstream: https://github.com/ansible/ansible-modules-extras/commit/7c3999a92a1cd856ff9bc8913a93ff1aee8bffc3"]},"tags":{},"packages":[{"name":"ansible","source":"https://ubuntu.com/security/cve?package=ansible","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ansible","debian":"https://tracker.debian.org/pkg/ansible","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.0.2.0-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.0.2.0-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.0.2.0-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.0.2.0-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1.0-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.0.0.2-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.0.2.0-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.0.2.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4423","published":"2016-06-01T22:59:00","updated_at":"2025-08-26T11:54:20.464025+00:00","description":"\nThe attemptAuthentication function in\nComponent/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php\nin Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and\n3.0.x before 3.0.6 does not limit the length of a username stored in a\nsession, which allows remote attackers to cause a denial of service\n(session storage consumption) via a series of authentication attempts with\nlong, non-existent usernames.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/symfony/symfony/pull/18733","https://symfony.com/blog/cve-2016-4423-large-username-storage-in-session","https://www.cve.org/CVERecord?id=CVE-2016-4423"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.6+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.8.6+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.4.15+dfsg-2ubuntu4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1902","published":"2016-06-01T22:59:00","updated_at":"2025-08-25T21:55:45.113090+00:00","description":"\nThe nextBytes function in the SecureRandom class in Symfony before 2.3.37,\n2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate\nrandom numbers when used with PHP 5.x without the paragonie/random_compat\nlibrary and the openssl_random_pseudo_bytes function fails, which makes it\neasier for attackers to defeat cryptographic protection mechanisms via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://symfony.com/blog/cve-2016-1902-securerandom-s-fallback-not-secure-when-openssl-fails","https://github.com/symfony/symfony/pull/17359","https://www.cve.org/CVERecord?id=CVE-2016-1902"],"bugs":[""],"patches":{"symfony":["upstream: https://github.com/symfony/symfony/pull/17359"]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.9+dfsg-1, 2.3.37, 2.6.13, and 2.7.9","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.7.9+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4432","published":"2016-06-01T20:59:00","updated_at":"2025-08-25T22:03:20.585105+00:00","description":"\nThe AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java\nbefore 6.0.3 might allow remote attackers to bypass authentication and\nconsequently perform actions via vectors related to connection state\nlogging.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"This issue affects only qpid-java."}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://issues.apache.org/jira/browse/QPID-7257","https://www.cve.org/CVERecord?id=CVE-2016-4432"],"bugs":[""],"patches":{"qpid-cpp":[]},"tags":{},"packages":[{"name":"qpid-cpp","source":"https://ubuntu.com/security/cve?package=qpid-cpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qpid-cpp","debian":"https://tracker.debian.org/pkg/qpid-cpp","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3697","published":"2016-06-01T20:59:00","updated_at":"2025-08-25T21:59:56.474755+00:00","description":"\nlibcontainer/user/user.go in runC before 0.1.0, as used in Docker before\n1.11.2, improperly treats a numeric UID as a potential username, which\nallows local users to gain privileges via a numeric username in the\npassword file in a container.","ubuntu_description":"","notes":[{"author":"leosilva","note":"debian claims that the code is not present in docker.io.\nin all the case runc is not affected anyway."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/opencontainers/runc/commit/69af385de62ea68e2e608335cffbb0f4aa3db091 (runc, v0.1.0)","https://github.com/docker/docker/commit/da38ac6c79fe902ed0687afc73d731c95c6d491a (docker)","https://www.cve.org/CVERecord?id=CVE-2016-3697"],"bugs":[""],"patches":{"runc":[],"docker.io":[]},"tags":{},"packages":[{"name":"docker.io","source":"https://ubuntu.com/security/cve?package=docker.io","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=docker.io","debian":"https://tracker.debian.org/pkg/docker.io","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"runc","source":"https://ubuntu.com/security/cve?package=runc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=runc","debian":"https://tracker.debian.org/pkg/runc","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.1.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.0.0~rc2+docker1.12.6-0ubuntu1~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.0.0~rc2+docker1.12.6-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3094","published":"2016-06-01T20:59:00","updated_at":"2025-08-25T21:59:12.536069+00:00","description":"\nPlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is\nconfigured to allow plaintext passwords, allows remote attackers to cause a\ndenial of service (broker termination) via a crafted authentication\nattempt, which triggers an uncaught exception.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"This problem affects only qpid-java."}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://issues.apache.org/jira/browse/QPID-7271","https://www.cve.org/CVERecord?id=CVE-2016-3094"],"bugs":[""],"patches":{"qpid-cpp":[]},"tags":{},"packages":[{"name":"qpid-cpp","source":"https://ubuntu.com/security/cve?package=qpid-cpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qpid-cpp","debian":"https://tracker.debian.org/pkg/qpid-cpp","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3088","published":"2016-06-01T20:59:00","updated_at":"2025-08-25T21:59:12.536069+00:00","description":"\nThe Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows\nremote attackers to upload and execute arbitrary files via an HTTP PUT\nfollowed by an HTTP MOVE request.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Affects \"Apache ActiveMQ 5.0.0 - 5.13.2\""},{"author":"msalvatore","note":"No upstream patch available for 5.13. Fileserver feature has been completely\nremoved starting with 5.14.0"},{"author":"noam-ns","note":"xenial uses 5.13, in which Fileserver exists but is disabled by default"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt","https://www.cve.org/CVERecord?id=CVE-2016-3088","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.13.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"5.14.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-2175","published":"2016-06-01T20:59:00","updated_at":"2025-08-26T11:54:05.517589+00:00","description":"\nApache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly\ninitialize the XML parsers, which allows context-dependent attackers to\nconduct XML External Entity (XXE) attacks via a crafted PDF.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2016/q2/419","https://www.cve.org/CVERecord?id=CVE-2016-2175"],"bugs":[""],"patches":{"libpdfbox-java":["upstream: https://svn.apache.org/viewvc?view=revision&revision=1739564"]},"tags":{},"packages":[{"name":"libpdfbox-java","source":"https://ubuntu.com/security/cve?package=libpdfbox-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpdfbox-java","debian":"https://tracker.debian.org/pkg/libpdfbox-java","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.12","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:1.8.7+dfsg-1+deb8u1build0.15.10.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:1.8.12-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5126","published":"2016-06-01T00:00:00","updated_at":"2025-08-25T22:04:46.346133+00:00","description":"\nHeap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c\nin QEMU allows local guest OS users to cause a denial of service (QEMU\nprocess crash) or possibly execute arbitrary code via a crafted iSCSI\nasynchronous I/O ioctl call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/qemu-block/2016-05/msg00779.html","http://www.openwall.com/lists/oss-security/2016/05/30/6","https://ubuntu.com/security/notices/USN-3047-1","https://www.cve.org/CVERecord?id=CVE-2016-5126"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=826151","https://bugzilla.redhat.com/show_bug.cgi?id=1340924"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commitdiff;h=a6b3167fa0e825aebb5a7cd8b437b6d41584a196"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.26","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3047-1"],"notices":[{"id":"USN-3047-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2016-08-04T18:23:47.503700","description":"Li Qiang discovered that QEMU incorrectly handled 53C9X Fast SCSI\ncontroller emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service, or possibly\nexecute arbitrary code on the host. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-4439, CVE-2016-4441, CVE-2016-5238, CVE-2016-5338, CVE-2016-6351)\n\nLi Qiang and Qinghao Tang discovered that QEMU incorrectly handled the\nVMWare VGA module. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service, or possibly\nto obtain sensitive host memory. (CVE-2016-4453, CVE-2016-4454)\n\nLi Qiang discovered that QEMU incorrectly handled VMWARE PVSCSI paravirtual\nSCSI bus emulation support. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\nThis issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-4952)\n\nLi Qiang discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2 Host\nBus Adapter emulation support. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service, or\npossibly to obtain sensitive host memory. This issue only applied to Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5105, CVE-2016-5106,\nCVE-2016-5107, CVE-2016-5337)\n\nIt was discovered that QEMU incorrectly handled certain iSCSI asynchronous\nI/O ioctl calls. An attacker inside the guest could use this issue to cause\nQEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\nThis issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-5126)\n\nZhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-5403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.29","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.29"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.26","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.3","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-4439","CVE-2016-4441","CVE-2016-4453","CVE-2016-4454","CVE-2016-4952","CVE-2016-5105","CVE-2016-5106","CVE-2016-5107","CVE-2016-5126","CVE-2016-5238","CVE-2016-5337","CVE-2016-5338","CVE-2016-5403","CVE-2016-6351"]}]},{"id":"CVE-2016-4454","published":"2016-06-01T00:00:00","updated_at":"2025-08-25T22:03:30.177656+00:00","description":"\nThe vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows\nlocal guest OS administrators to obtain sensitive host memory information\nor cause a denial of service (QEMU process crash) by changing FIFO\nregisters and issuing a VGA command, which triggers an out-of-bounds read.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg05271.html","https://ubuntu.com/security/notices/USN-3047-1","https://www.cve.org/CVERecord?id=CVE-2016-4454"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1336429"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=521360267876d3b6518b328051a2e56bca55bef8","upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=c2e3c54d3960bc53bfa3a5ce7ea7a050b9be267e","upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=7e486f7577764a07aa35588e119903c80a5c30a2"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.26","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.3","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.29","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3047-1"],"notices":[{"id":"USN-3047-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2016-08-04T18:23:47.503700","description":"Li Qiang discovered that QEMU incorrectly handled 53C9X Fast SCSI\ncontroller emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service, or possibly\nexecute arbitrary code on the host. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-4439, CVE-2016-4441, CVE-2016-5238, CVE-2016-5338, CVE-2016-6351)\n\nLi Qiang and Qinghao Tang discovered that QEMU incorrectly handled the\nVMWare VGA module. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service, or possibly\nto obtain sensitive host memory. (CVE-2016-4453, CVE-2016-4454)\n\nLi Qiang discovered that QEMU incorrectly handled VMWARE PVSCSI paravirtual\nSCSI bus emulation support. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\nThis issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-4952)\n\nLi Qiang discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2 Host\nBus Adapter emulation support. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service, or\npossibly to obtain sensitive host memory. This issue only applied to Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5105, CVE-2016-5106,\nCVE-2016-5107, CVE-2016-5337)\n\nIt was discovered that QEMU incorrectly handled certain iSCSI asynchronous\nI/O ioctl calls. An attacker inside the guest could use this issue to cause\nQEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\nThis issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-5126)\n\nZhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-5403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.29","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.29"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.26","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.3","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-4439","CVE-2016-4441","CVE-2016-4453","CVE-2016-4454","CVE-2016-4952","CVE-2016-5105","CVE-2016-5106","CVE-2016-5107","CVE-2016-5126","CVE-2016-5238","CVE-2016-5337","CVE-2016-5338","CVE-2016-5403","CVE-2016-6351"]}]},{"id":"CVE-2016-4453","published":"2016-06-01T00:00:00","updated_at":"2025-08-25T22:03:25.431832+00:00","description":"\nThe vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows\nlocal guest OS administrators to cause a denial of service (infinite loop\nand QEMU process crash) via a VGA command.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Marking as negligible because a privileged user inside the guest\ncould shut down the guest OS."}],"codename":null,"priority":"negligible","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/qemu-devel/2016-05/msg05270.html","https://ubuntu.com/security/notices/USN-3047-1","https://www.cve.org/CVERecord?id=CVE-2016-4453"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1336650"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=4e68a0ee17dad7b8d870df0081d4ab2e079016c2"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.26","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.29","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3047-1"],"notices":[{"id":"USN-3047-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2016-08-04T18:23:47.503700","description":"Li Qiang discovered that QEMU incorrectly handled 53C9X Fast SCSI\ncontroller emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service, or possibly\nexecute arbitrary code on the host. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. This issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-4439, CVE-2016-4441, CVE-2016-5238, CVE-2016-5338, CVE-2016-6351)\n\nLi Qiang and Qinghao Tang discovered that QEMU incorrectly handled the\nVMWare VGA module. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service, or possibly\nto obtain sensitive host memory. (CVE-2016-4453, CVE-2016-4454)\n\nLi Qiang discovered that QEMU incorrectly handled VMWARE PVSCSI paravirtual\nSCSI bus emulation support. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\nThis issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-4952)\n\nLi Qiang discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2 Host\nBus Adapter emulation support. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service, or\npossibly to obtain sensitive host memory. This issue only applied to Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5105, CVE-2016-5106,\nCVE-2016-5107, CVE-2016-5337)\n\nIt was discovered that QEMU incorrectly handled certain iSCSI asynchronous\nI/O ioctl calls. An attacker inside the guest could use this issue to cause\nQEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\nThis issue only applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-5126)\n\nZhenhao Hong discovered that QEMU incorrectly handled the Virtio module. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-5403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.29","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.29"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.26","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.26","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.3","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-4439","CVE-2016-4441","CVE-2016-4453","CVE-2016-4454","CVE-2016-4952","CVE-2016-5105","CVE-2016-5106","CVE-2016-5107","CVE-2016-5126","CVE-2016-5238","CVE-2016-5337","CVE-2016-5338","CVE-2016-5403","CVE-2016-6351"]}]},{"id":"CVE-2016-1234","published":"2016-06-01T00:00:00","updated_at":"2025-08-25T21:53:52.435503+00:00","description":"\nStack-based buffer overflow in the glob implementation in GNU C Library\n(aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows\ncontext-dependent attackers to cause a denial of service (crash) via a long\nname.","ubuntu_description":"\nAlexander Cherepanov discovered a stack-based buffer overflow in the\nglob implementation of the GNU C Library. An attacker could use this\nto specially craft a directory layout and cause a denial of service.","notes":[{"author":"sbeattie","note":"see glibc bug for reproducer\nrequires malicious fs layout"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3239-1","https://www.cve.org/CVERecord?id=CVE-2016-1234"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=19779","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1234"],"patches":{"eglibc":[],"glibc":["upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=5171f3079f2cc53e0548fc4967361f4d1ce9d7ea"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.19-0ubuntu6.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"zesty","status":"not-affected","description":"2.24-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.24","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.23-0ubuntu6","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.24-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3239-1"],"notices":[{"id":"USN-3239-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2017-03-21T02:58:45.626524","description":"It was discovered that the GNU C Library incorrectly handled the\nstrxfrm() function. An attacker could use this issue to cause a denial\nof service or possibly execute arbitrary code. This issue only affected\nUbuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)\n\nIt was discovered that an integer overflow existed in the\n_IO_wstr_overflow() function of the GNU C Library. An attacker could\nuse this to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04\nLTS. (CVE-2015-8983)\n\nIt was discovered that the fnmatch() function in the GNU C Library\ndid not properly handle certain malformed patterns. An attacker could\nuse this to cause a denial of service. This issue only affected Ubuntu\n12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8984)\n\nAlexander Cherepanov discovered a stack-based buffer overflow in the\nglob implementation of the GNU C Library. An attacker could use this\nto specially craft a directory layout and cause a denial of service.\n(CVE-2016-1234)\n\nFlorian Weimer discovered a NULL pointer dereference in the DNS\nresolver of the GNU C Library. An attacker could use this to cause\na denial of service. (CVE-2015-5180)\n\nMichael Petlan discovered an unbounded stack allocation in the\ngetaddrinfo() function of the GNU C Library. An attacker could use\nthis to cause a denial of service. (CVE-2016-3706)\n\nAldy Hernandez discovered an unbounded stack allocation in the sunrpc\nimplementation in the GNU C Library. An attacker could use this to\ncause a denial of service. (CVE-2016-4429)\n\nTim Ruehsen discovered that the getaddrinfo() implementation in the\nGNU C Library did not properly track memory allocations. An attacker\ncould use this to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS. (CVE-2016-5417)\n\nAndreas Schwab discovered that the GNU C Library on ARM 32-bit\nplatforms did not properly set up execution contexts. An attacker\ncould use this to cause a denial of service. (CVE-2016-6323)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.16","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.16"}],"trusty":[{"name":"eglibc","version":"2.19-0ubuntu6.10","description":"GNU C Library","is_source":true},{"name":"eglibc-source","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"glibc-doc","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-dev-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-pic","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-prof","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-dns-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-files-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"multiarch-support","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"nscd","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"}],"xenial":[{"name":"glibc","version":"2.23-0ubuntu6","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"glibc-source","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-dev-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6","version":"2.23-0ubuntu6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-pic","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-udeb","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales-all","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"multiarch-support","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"nscd","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5180","CVE-2015-8982","CVE-2015-8983","CVE-2015-8984","CVE-2016-1234","CVE-2016-3706","CVE-2016-4429","CVE-2016-5417","CVE-2016-6323"]}]},{"id":"CVE-2015-8875","published":"2016-06-01T00:00:00","updated_at":"2025-08-25T21:49:40.296810+00:00","description":"\nMultiple integer overflows in the (1) pixops_composite_nearest, (2)\npixops_composite_color_nearest, and (3) pixops_process functions in\npixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause\na denial of service (application crash) or possibly execute arbitrary code\nvia a crafted image, which triggers a heap-based buffer overflow.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"in their wheezy update, debian identified this fix as\nCVE-2015-7674-part2.patch (in 2.26.1-1+deb7u4)."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/05/12/3","https://ubuntu.com/security/notices/USN-3085-1","https://www.cve.org/CVERecord?id=CVE-2015-8875"],"bugs":[""],"patches":{"gdk-pixbuf":["upstream: https://git.gnome.org/browse/gdk-pixbuf/commit/?id=dbfe8f70471864818bf458a39c8a99640895bd22"]},"tags":{},"packages":[{"name":"gdk-pixbuf","source":"https://ubuntu.com/security/cve?package=gdk-pixbuf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdk-pixbuf","debian":"https://tracker.debian.org/pkg/gdk-pixbuf","statuses":[{"release_codename":"precise","status":"released","description":"2.26.1-1ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.30.7-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.32.2, 2.34.0","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.32.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.34.0-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.34.0-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3085-1"],"notices":[{"id":"USN-3085-1","title":"GDK-PixBuf vulnerabilities","summary":"GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2016-09-21T21:29:42.952519","description":"It was discovered that the GDK-PixBuf library did not properly handle specially\ncrafted bmp images, leading to a heap-based buffer overflow. If a user or\nautomated system were tricked into opening a specially crafted bmp file, a\nremote attacker could use this flaw to cause GDK-PixBuf to crash, resulting\nin a denial of service, or possibly execute arbitrary code. This issue only\naffected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-7552)\n\nIt was discovered that the GDK-PixBuf library contained an integer overflow\nwhen handling certain images. If a user or automated system were tricked into\nopening a crafted image file, a remote attacker could use this flaw to cause\nGDK-PixBuf to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8875)\n\nFranco Costantini discovered that the GDK-PixBuf library contained an \nout-of-bounds write error when parsing an ico file. If a user or automated\nsystem were tricked into opening a crafted ico file, a remote attacker could\nuse this flaw to cause GDK-PixBuf to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-6352)\n","is_hidden":false,"release_packages":{"precise":[{"name":"gdk-pixbuf","version":"2.26.1-1ubuntu1.5","description":"GDK-Pixbuf library","is_source":true},{"name":"libgdk-pixbuf2.0-0","version":"2.26.1-1ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.26.1-1ubuntu1.5"}],"trusty":[{"name":"gdk-pixbuf","version":"2.30.7-0ubuntu1.6","description":"GDK-Pixbuf library","is_source":true},{"name":"gir1.2-gdkpixbuf-2.0","version":"2.30.7-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.6","pocket":"security"},{"name":"libgdk-pixbuf2.0-0","version":"2.30.7-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.6","pocket":"security"},{"name":"libgdk-pixbuf2.0-0-udeb","version":"2.30.7-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.6","pocket":"security"},{"name":"libgdk-pixbuf2.0-common","version":"2.30.7-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.6","pocket":"security"},{"name":"libgdk-pixbuf2.0-dev","version":"2.30.7-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.6","pocket":"security"},{"name":"libgdk-pixbuf2.0-doc","version":"2.30.7-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.6","pocket":"security"}],"xenial":[{"name":"gdk-pixbuf","version":"2.32.2-1ubuntu1.2","description":"GDK-Pixbuf library","is_source":true},{"name":"gir1.2-gdkpixbuf-2.0","version":"2.32.2-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.2","pocket":"security"},{"name":"libgdk-pixbuf2.0-0","version":"2.32.2-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.2","pocket":"security"},{"name":"libgdk-pixbuf2.0-0-udeb","version":"2.32.2-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.2","pocket":"security"},{"name":"libgdk-pixbuf2.0-common","version":"2.32.2-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.2","pocket":"security"},{"name":"libgdk-pixbuf2.0-dev","version":"2.32.2-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.2","pocket":"security"},{"name":"libgdk-pixbuf2.0-doc","version":"2.32.2-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-7552","CVE-2015-8875","CVE-2016-6352"]}]},{"id":"CVE-2016-1582","published":"2016-05-31T18:00:00","updated_at":"2025-08-25T21:54:26.986122+00:00","description":"\nLXD before 2.0.2 does not properly set permissions when switching an\nunprivileged container into privileged mode, which allows local users to\naccess arbitrary world readable paths in the container directory via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2988-1","https://www.cve.org/CVERecord?id=CVE-2016-1582"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1584230"],"patches":{"lxd":[]},"tags":{},"packages":[{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"0.20-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.0.2-0ubuntu1~16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2988-1"],"notices":[{"id":"USN-2988-1","title":"LXD vulnerabilities","summary":"Several security issues were fixed in LXD.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-05-31T18:10:23.974347","description":"Robie Basak discovered that LXD incorrectly set permissions when setting up\na loop based ZFS pool. A local attacker could use this issue to copy and\nread the data of any LXD container. (CVE-2016-1581)\n\nRobie Basak discovered that LXD incorrectly set permissions when switching\nan unprivileged container into privileged mode. A local attacker could use\nthis issue to access any world readable path in the container directory,\nincluding setuid binaries. (CVE-2016-1582)\n","is_hidden":false,"release_packages":{"wily":[{"name":"lxd","version":"0.20-0ubuntu4.2","description":"Container hypervisor based on LXC","is_source":true},{"name":"lxd","version":"0.20-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/0.20-0ubuntu4.2"}],"xenial":[{"name":"lxd","version":"2.0.2-0ubuntu1~16.04.1","description":"Container hypervisor based on LXC","is_source":true},{"name":"golang-github-lxc-lxd-dev","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxc2","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxd","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxd-client","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxd-tools","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-1581","CVE-2016-1582"]}]},{"id":"CVE-2016-1581","published":"2016-05-31T18:00:00","updated_at":"2025-08-25T21:54:26.986122+00:00","description":"\nLXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img\nwhen setting up a loop based ZFS pool, which allows local users to copy and\nread data from arbitrary containers via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2988-1","https://www.cve.org/CVERecord?id=CVE-2016-1581"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/1584230"],"patches":{"lxd":[]},"tags":{},"packages":[{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"0.20-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.0.2-0ubuntu1~16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2988-1"],"notices":[{"id":"USN-2988-1","title":"LXD vulnerabilities","summary":"Several security issues were fixed in LXD.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-05-31T18:10:23.974347","description":"Robie Basak discovered that LXD incorrectly set permissions when setting up\na loop based ZFS pool. A local attacker could use this issue to copy and\nread the data of any LXD container. (CVE-2016-1581)\n\nRobie Basak discovered that LXD incorrectly set permissions when switching\nan unprivileged container into privileged mode. A local attacker could use\nthis issue to access any world readable path in the container directory,\nincluding setuid binaries. (CVE-2016-1582)\n","is_hidden":false,"release_packages":{"wily":[{"name":"lxd","version":"0.20-0ubuntu4.2","description":"Container hypervisor based on LXC","is_source":true},{"name":"lxd","version":"0.20-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/0.20-0ubuntu4.2"}],"xenial":[{"name":"lxd","version":"2.0.2-0ubuntu1~16.04.1","description":"Container hypervisor based on LXC","is_source":true},{"name":"golang-github-lxc-lxd-dev","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxc2","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxd","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxd-client","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"},{"name":"lxd-tools","version":"2.0.2-0ubuntu1~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":"https://launchpad.net/ubuntu/+source/lxd/2.0.2-0ubuntu1~16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-1581","CVE-2016-1582"]}]},{"id":"CVE-2016-4450","published":"2016-05-31T00:00:00","updated_at":"2025-08-25T22:03:25.431832+00:00","description":"\nos/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows\nremote attackers to cause a denial of service (NULL pointer dereference and\nworker process crash) via a crafted request, involving writing a client\nrequest body to a temporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://mailman.nginx.org/pipermail/nginx-announce/2016/000179.html","https://ubuntu.com/security/notices/USN-2991-1","https://www.cve.org/CVERecord?id=CVE-2016-4450"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1587577"],"patches":{"nginx":["upstream: http://nginx.org/download/patch.2016.write.txt","upstream: http://nginx.org/download/patch.2016.write2.txt"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"xenial","status":"released","description":"1.10.0-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.10.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.10.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.1,1.11.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.9.3-1ubuntu1.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2991-1"],"notices":[{"id":"USN-2991-1","title":"nginx vulnerability","summary":"nginx could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-06-02T17:03:40.805452","description":"It was discovered that nginx incorrectly handled saving client request\nbodies to temporary files. A remote attacker could possibly use this issue\nto cause nginx to crash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.5","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5","pocket":"security"}],"wily":[{"name":"nginx","version":"1.9.3-1ubuntu1.2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx-core","version":"1.9.3-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.9.3-1ubuntu1.2"},{"name":"nginx-extras","version":"1.9.3-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.9.3-1ubuntu1.2"},{"name":"nginx-full","version":"1.9.3-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.9.3-1ubuntu1.2"},{"name":"nginx-light","version":"1.9.3-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.9.3-1ubuntu1.2"}],"xenial":[{"name":"nginx","version":"1.10.0-0ubuntu0.16.04.2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.10.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"nginx-common","version":"1.10.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"nginx-core","version":"1.10.0-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"nginx-doc","version":"1.10.0-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"nginx-extras","version":"1.10.0-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"nginx-full","version":"1.10.0-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2","pocket":"security"},{"name":"nginx-light","version":"1.10.0-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-4450"]}]},{"id":"CVE-2016-1695","published":"2016-05-31T00:00:00","updated_at":"2025-08-25T21:55:11.329165+00:00","description":"\nMultiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63\nallow attackers to cause a denial of service or possibly have other impact\nvia unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html","https://ubuntu.com/security/notices/USN-2992-1","https://www.cve.org/CVERecord?id=CVE-2016-1695"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"51.0.2704.79-0ubuntu0.14.04.1.1121","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"51.0.2704.63-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"51.0.2704.79-0ubuntu0.16.04.1.1242","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.15.7-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.15.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.15.7-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.15.7-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2992-1"],"notices":[{"id":"USN-2992-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-06-06T15:26:12.476756","description":"An unspecified security issue was discovered in Blink. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1673)\n\nAn issue was discovered with Document reattachment in Blink in some\ncircumstances. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to bypass same-origin\nrestrictions. (CVE-2016-1675)\n\nA type confusion bug was discovered in V8. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to obtain sensitive information. (CVE-2016-1677)\n\nA heap overflow was discovered in V8. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\ncause a denial of service (application crash) or execute arbitrary code.\n(CVE-2016-1678)\n\nA use-after-free was discovered in the V8ValueConverter implementation in\nChromium in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service (application crash) or execute arbitrary code.\n(CVE-2016-1679)\n\nA use-after-free was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service (application crash) or execute arbitrary\ncode. (CVE-2016-1680)\n\nA security issue was discovered in ServiceWorker registration in Blink in\nsome circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to bypass\nContent Security Policy (CSP) protections. (CVE-2016-1682)\n\nAn out-of-bounds memory access was discovered in libxslt. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service (application crash)\nor execute arbitrary code. (CVE-2016-1683)\n\nAn integer overflow was discovered in libxslt. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service (application crash or resource\nconsumption). (CVE-2016-1684)\n\nAn out-of-bounds read was discovered in the regular expression\nimplementation in V8. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to cause a\ndenial of service (application crash). (CVE-2016-1688)\n\nA heap overflow was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service (application crash) or execute arbitrary\ncode. (CVE-2016-1689)\n\nA heap overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service (application crash) or execute arbitrary\ncode. (CVE-2016-1691)\n\nIt was discovered that Blink permits cross-origin loading of stylesheets\nby a service worker even when the stylesheet download has an incorrect\nMIME type. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to bypass same-origin\nrestrictions. (CVE-2016-1692)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service (application crash) or execute arbitrary code. (CVE-2016-1695,\nCVE-2016-1703)\n\nIt was discovered that Blink does not prevent frame navigation during\nDocumentLoader detach operations. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\nbypass same-origin restrictions. (CVE-2016-1697)\n\nA parameter sanitization bug was discovered in the devtools subsystem in\nBlink. An attacker could potentially exploit this to bypass intended\naccess restrictions. (CVE-2016-1699)\n\nAn out-of-bounds read was discovered in Skia. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service (application crash).\n(CVE-2016-1702)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.15.7-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.15.7-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.15.7-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.15.10.1"}],"xenial":[{"name":"oxide-qt","version":"1.15.7-0ubuntu0.16.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-1673","CVE-2016-1675","CVE-2016-1677","CVE-2016-1678","CVE-2016-1679","CVE-2016-1680","CVE-2016-1682","CVE-2016-1683","CVE-2016-1684","CVE-2016-1688","CVE-2016-1689","CVE-2016-1691","CVE-2016-1692","CVE-2016-1695","CVE-2016-1697","CVE-2016-1699","CVE-2016-1702","CVE-2016-1703"]}]},{"id":"CVE-2016-1692","published":"2016-05-31T00:00:00","updated_at":"2025-08-25T21:55:11.329165+00:00","description":"\nWebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google\nChrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets\nby a ServiceWorker even when the stylesheet download has an incorrect MIME\ntype, which allows remote attackers to bypass the Same Origin Policy via a\ncrafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.html","https://ubuntu.com/security/notices/USN-2992-1","https://www.cve.org/CVERecord?id=CVE-2016-1692"],"bugs":[""],"patches":{"chromium-browser":[],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"51.0.2704.79-0ubuntu0.14.04.1.1121","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"51.0.2704.63-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"51.0.2704.79-0ubuntu0.16.04.1.1242","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.15.7-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.15.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.15.7-0ubuntu0.15.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.15.7-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2992-1"],"notices":[{"id":"USN-2992-1","title":"Oxide vulnerabilities","summary":"Several security issues were fixed in Oxide.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-06-06T15:26:12.476756","description":"An unspecified security issue was discovered in Blink. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to bypass same-origin restrictions.\n(CVE-2016-1673)\n\nAn issue was discovered with Document reattachment in Blink in some\ncircumstances. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to bypass same-origin\nrestrictions. (CVE-2016-1675)\n\nA type confusion bug was discovered in V8. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to obtain sensitive information. (CVE-2016-1677)\n\nA heap overflow was discovered in V8. If a user were tricked in to opening\na specially crafted website, an attacker could potentially exploit this to\ncause a denial of service (application crash) or execute arbitrary code.\n(CVE-2016-1678)\n\nA use-after-free was discovered in the V8ValueConverter implementation in\nChromium in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service (application crash) or execute arbitrary code.\n(CVE-2016-1679)\n\nA use-after-free was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service (application crash) or execute arbitrary\ncode. (CVE-2016-1680)\n\nA security issue was discovered in ServiceWorker registration in Blink in\nsome circumstances. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to bypass\nContent Security Policy (CSP) protections. (CVE-2016-1682)\n\nAn out-of-bounds memory access was discovered in libxslt. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service (application crash)\nor execute arbitrary code. (CVE-2016-1683)\n\nAn integer overflow was discovered in libxslt. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service (application crash or resource\nconsumption). (CVE-2016-1684)\n\nAn out-of-bounds read was discovered in the regular expression\nimplementation in V8. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit this to cause a\ndenial of service (application crash). (CVE-2016-1688)\n\nA heap overflow was discovered in Chromium. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service (application crash) or execute arbitrary\ncode. (CVE-2016-1689)\n\nA heap overflow was discovered in Skia. If a user were tricked in to\nopening a specially crafted website, an attacker could potentially exploit\nthis to cause a denial of service (application crash) or execute arbitrary\ncode. (CVE-2016-1691)\n\nIt was discovered that Blink permits cross-origin loading of stylesheets\nby a service worker even when the stylesheet download has an incorrect\nMIME type. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to bypass same-origin\nrestrictions. (CVE-2016-1692)\n\nMultiple security issues were discovered in Chromium. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit these to read uninitialized memory, cause a denial\nof service (application crash) or execute arbitrary code. (CVE-2016-1695,\nCVE-2016-1703)\n\nIt was discovered that Blink does not prevent frame navigation during\nDocumentLoader detach operations. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\nbypass same-origin restrictions. (CVE-2016-1697)\n\nA parameter sanitization bug was discovered in the devtools subsystem in\nBlink. An attacker could potentially exploit this to bypass intended\naccess restrictions. (CVE-2016-1699)\n\nAn out-of-bounds read was discovered in Skia. If a user were tricked in\nto opening a specially crafted website, an attacker could potentially\nexploit this to cause a denial of service (application crash).\n(CVE-2016-1702)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"oxide-qt","version":"1.15.7-0ubuntu0.14.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqmlscene","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-chromedriver","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.15.7-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.14.04.1","pocket":"security"}],"wily":[{"name":"oxide-qt","version":"1.15.7-0ubuntu0.15.10.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqtcore0","version":"1.15.7-0ubuntu0.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.15.10.1"}],"xenial":[{"name":"oxide-qt","version":"1.15.7-0ubuntu0.16.04.1","description":"Web browser engine for Qt (QML plugin)","is_source":true},{"name":"liboxideqt-qmlplugin","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtcore-dev","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtcore0","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtquick-dev","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"liboxideqtquick0","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"oxideqt-codecs","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"},{"name":"oxideqt-codecs-extra","version":"1.15.7-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/oxide-qt","version_link":"https://launchpad.net/ubuntu/+source/oxide-qt/1.15.7-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-1673","CVE-2016-1675","CVE-2016-1677","CVE-2016-1678","CVE-2016-1679","CVE-2016-1680","CVE-2016-1682","CVE-2016-1683","CVE-2016-1684","CVE-2016-1688","CVE-2016-1689","CVE-2016-1691","CVE-2016-1692","CVE-2016-1695","CVE-2016-1697","CVE-2016-1699","CVE-2016-1702","CVE-2016-1703"]}]}],"offset":60700,"limit":20,"total_results":79316}