{"cves":[{"id":"CVE-2016-4080","published":"2016-04-25T10:59:00","updated_at":"2025-08-25T22:02:13.172347+00:00","description":"\nepan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x\nbefore 1.12.11 and 2.0.x before 2.0.3 misparses timestamp fields, which\nallows remote attackers to cause a denial of service (out-of-bounds read\nand application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=ad097385c05c370440fb810e67f811398efc0ea0","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12242","http://www.wireshark.org/security/wnpa-sec-2016-23.html","https://www.cve.org/CVERecord?id=CVE-2016-4080"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.2.6+g32dac6a-2ubuntu0.16.04","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4079","published":"2016-04-25T10:59:00","updated_at":"2025-08-25T22:02:13.172347+00:00","description":"\nepan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x\nbefore 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers,\nwhich allows remote attackers to cause a denial of service (out-of-bounds\nwrite and application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=4cdc9eeba58f866bd5f273e9c5b3876857a7a4bf","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12206","http://www.wireshark.org/security/wnpa-sec-2016-22.html","https://www.cve.org/CVERecord?id=CVE-2016-4079"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4078","published":"2016-04-25T10:59:00","updated_at":"2025-08-25T22:02:13.172347+00:00","description":"\nThe IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x\nbefore 2.0.3 does not properly restrict element lists, which allows remote\nattackers to cause a denial of service (deep recursion and application\ncrash) via a crafted packet, related to epan/dissectors/packet-capwap.c and\nepan/dissectors/packet-ieee80211.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=e2745d741ec11f395d41c0aafa24df9dec136399","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12187","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11824","http://www.wireshark.org/security/wnpa-sec-2016-21.html","https://www.cve.org/CVERecord?id=CVE-2016-4078"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4077","published":"2016-04-25T10:59:00","updated_at":"2025-08-25T22:02:13.172347+00:00","description":"\nepan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 relies on\nincorrect special-case handling of truncated Tvb data structures, which\nallows remote attackers to cause a denial of service (use-after-free and\napplication crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=c5b2c1e8f40cee913bd70fcc00284483b3c92fcd","https://code.google.com/p/google-security-research/issues/detail?id=651","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11799","http://www.wireshark.org/security/wnpa-sec-2016-20.html","https://www.cve.org/CVERecord?id=CVE-2016-4077"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4076","published":"2016-04-25T10:59:00","updated_at":"2025-08-25T22:02:13.172347+00:00","description":"\nepan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x\nbefore 2.0.3 does not properly initialize memory for search patterns, which\nallows remote attackers to cause a denial of service (application crash)\nvia a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=ea8e6955fcff21333c203bc00f69d5025761459b","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11591","http://www.wireshark.org/security/wnpa-sec-2016-19.html","https://www.cve.org/CVERecord?id=CVE-2016-4076"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4006","published":"2016-04-25T10:59:00","updated_at":"2025-08-25T22:01:56.770736+00:00","description":"\nepan/proto.c in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does\nnot limit the protocol-tree depth, which allows remote attackers to cause a\ndenial of service (stack memory consumption and application crash) via a\ncrafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=8dc9551e1d56290e6f7f02cc38b77e1d211fd4a5","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12268","http://www.wireshark.org/security/wnpa-sec-2016-25.html","https://www.cve.org/CVERecord?id=CVE-2016-4006"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.2.6+g32dac6a-2ubuntu0.16.04","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4073","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T22:02:13.172347+00:00","description":"\nMultiple integer overflows in the mbfl_strcut function in\next/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before\n5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of\nservice (application crash) or possibly execute arbitrary code via a\ncrafted mb_strcut call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://gist.github.com/smalyshev/d8355c96a657cc5dba70","http://www.openwall.com/lists/oss-security/2016/04/11/7","https://ubuntu.com/security/notices/USN-2952-1","https://ubuntu.com/security/notices/USN-2984-1","https://www.cve.org/CVERecord?id=CVE-2016-4073"],"bugs":["https://bugs.php.net/bug.php?id=71906"],"patches":{"php5":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=64f42c73efc58e88671ad76b6b6bc8e2b62713e1"],"php7.0":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=64f42c73efc58e88671ad76b6b6bc8e2b62713e1"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.22","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.20+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"5.6.11+dfsg-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.5-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.0.4-7ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2984-1"],"notices":[{"id":"USN-2984-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-05-24T17:31:16.121794","description":"It was discovered that the PHP Fileinfo component incorrectly handled\ncertain magic files. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)\n\nHans Jerry Illikainen discovered that the PHP Zip extension incorrectly\nhandled certain malformed Zip archives. A remote attacker could use this\nissue to cause PHP to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2016-3078)\n\nIt was discovered that PHP incorrectly handled invalid indexes in the\nSplDoublyLinkedList class. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3132)\n\nIt was discovered that the PHP rawurlencode() function incorrectly handled\nlarge strings. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS. (CVE-2016-4070)\n\nIt was discovered that the PHP php_snmp_error() function incorrectly\nhandled string formatting. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4071)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\nfilenames in archives. A remote attacker could use this issue to cause PHP\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4072)\n\nIt was discovered that the PHP mb_strcut() function incorrectly handled\nstring formatting. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4073)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\narchive files. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and\nUbuntu 15.10. (CVE-2016-4342, CVE-2016-4343)\n\nIt was discovered that the PHP bcpowmod() function incorrectly handled\nmemory. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code. \n(CVE-2016-4537, CVE-2016-4538)\n\nIt was discovered that the PHP XML parser incorrectly handled certain\nmalformed XML data. A remote attacker could possibly use this issue to\ncause PHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4539)\n\nIt was discovered that certain PHP grapheme functions incorrectly handled\nnegative offsets. A remote attacker could possibly use this issue to cause\nPHP to crash, resulting in a denial of service. (CVE-2016-4540,\nCVE-2016-4541)\n\nIt was discovered that PHP incorrectly handled certain malformed EXIF tags.\nA remote attacker could possibly use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2016-4542, CVE-2016-4543,\nCVE-2016-4544)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.23","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"}],"wily":[{"name":"php5","version":"5.6.11+dfsg-1ubuntu3.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cgi","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cli","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-fpm","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"}],"xenial":[{"name":"php7.0","version":"7.0.4-7ubuntu2.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"libphp7.0-embed","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bcmath","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bz2","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cgi","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cli","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-common","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-curl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-dev","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-enchant","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-fpm","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gd","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-imap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-interbase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-intl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-json","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-ldap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mbstring","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mcrypt","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mysql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-odbc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-opcache","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pgsql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-phpdbg","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pspell","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-readline","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-recode","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-snmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-soap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sqlite3","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sybase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-tidy","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xml","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xmlrpc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xsl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-zip","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8865","CVE-2016-3078","CVE-2016-3132","CVE-2016-4070","CVE-2016-4071","CVE-2016-4072","CVE-2016-4073","CVE-2016-4342","CVE-2016-4343","CVE-2016-4537","CVE-2016-4538","CVE-2016-4539","CVE-2016-4540","CVE-2016-4541","CVE-2016-4542","CVE-2016-4543","CVE-2016-4544"]}]},{"id":"CVE-2016-4072","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T22:02:08.342821+00:00","description":"\nThe Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x\nbefore 7.0.5 allows remote attackers to execute arbitrary code via a\ncrafted filename, as demonstrated by mishandling of \\0 characters by the\nphar_analyze_path function in ext/phar/phar.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://gist.github.com/smalyshev/80b5c2909832872f2ba2","http://www.openwall.com/lists/oss-security/2016/04/11/7","https://ubuntu.com/security/notices/USN-2952-1","https://ubuntu.com/security/notices/USN-2984-1","https://www.cve.org/CVERecord?id=CVE-2016-4072"],"bugs":["https://bugs.php.net/bug.php?id=71860"],"patches":{"php5":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=1e9b175204e3286d64dfd6c9f09151c31b5e099a"],"php7.0":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=1e9b175204e3286d64dfd6c9f09151c31b5e099a"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.22","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.20+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"5.6.11+dfsg-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.5-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.0.4-7ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2984-1"],"notices":[{"id":"USN-2984-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-05-24T17:31:16.121794","description":"It was discovered that the PHP Fileinfo component incorrectly handled\ncertain magic files. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)\n\nHans Jerry Illikainen discovered that the PHP Zip extension incorrectly\nhandled certain malformed Zip archives. A remote attacker could use this\nissue to cause PHP to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2016-3078)\n\nIt was discovered that PHP incorrectly handled invalid indexes in the\nSplDoublyLinkedList class. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3132)\n\nIt was discovered that the PHP rawurlencode() function incorrectly handled\nlarge strings. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS. (CVE-2016-4070)\n\nIt was discovered that the PHP php_snmp_error() function incorrectly\nhandled string formatting. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4071)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\nfilenames in archives. A remote attacker could use this issue to cause PHP\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4072)\n\nIt was discovered that the PHP mb_strcut() function incorrectly handled\nstring formatting. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4073)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\narchive files. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and\nUbuntu 15.10. (CVE-2016-4342, CVE-2016-4343)\n\nIt was discovered that the PHP bcpowmod() function incorrectly handled\nmemory. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code. \n(CVE-2016-4537, CVE-2016-4538)\n\nIt was discovered that the PHP XML parser incorrectly handled certain\nmalformed XML data. A remote attacker could possibly use this issue to\ncause PHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4539)\n\nIt was discovered that certain PHP grapheme functions incorrectly handled\nnegative offsets. A remote attacker could possibly use this issue to cause\nPHP to crash, resulting in a denial of service. (CVE-2016-4540,\nCVE-2016-4541)\n\nIt was discovered that PHP incorrectly handled certain malformed EXIF tags.\nA remote attacker could possibly use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2016-4542, CVE-2016-4543,\nCVE-2016-4544)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.23","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"}],"wily":[{"name":"php5","version":"5.6.11+dfsg-1ubuntu3.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cgi","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cli","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-fpm","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"}],"xenial":[{"name":"php7.0","version":"7.0.4-7ubuntu2.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"libphp7.0-embed","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bcmath","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bz2","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cgi","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cli","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-common","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-curl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-dev","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-enchant","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-fpm","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gd","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-imap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-interbase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-intl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-json","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-ldap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mbstring","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mcrypt","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mysql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-odbc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-opcache","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pgsql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-phpdbg","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pspell","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-readline","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-recode","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-snmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-soap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sqlite3","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sybase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-tidy","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xml","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xmlrpc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xsl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-zip","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8865","CVE-2016-3078","CVE-2016-3132","CVE-2016-4070","CVE-2016-4071","CVE-2016-4072","CVE-2016-4073","CVE-2016-4342","CVE-2016-4343","CVE-2016-4537","CVE-2016-4538","CVE-2016-4539","CVE-2016-4540","CVE-2016-4541","CVE-2016-4542","CVE-2016-4543","CVE-2016-4544"]}]},{"id":"CVE-2016-4071","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T22:02:08.342821+00:00","description":"\nFormat string vulnerability in the php_snmp_error function in\next/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before\n7.0.5 allows remote attackers to execute arbitrary code via format string\nspecifiers in an SNMP::get call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/04/11/7","https://ubuntu.com/security/notices/USN-2952-1","https://ubuntu.com/security/notices/USN-2984-1","https://www.cve.org/CVERecord?id=CVE-2016-4071"],"bugs":["https://bugs.php.net/bug.php?id=71704"],"patches":{"php5":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=6e25966544fb1d2f3d7596e060ce9c9269bbdcf8"],"php7.0":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=9c19a08b9daed6bae3071dd25742f59a59618823"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.20+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"5.6.11+dfsg-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.5-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.0.4-7ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2984-1"],"notices":[{"id":"USN-2984-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-05-24T17:31:16.121794","description":"It was discovered that the PHP Fileinfo component incorrectly handled\ncertain magic files. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)\n\nHans Jerry Illikainen discovered that the PHP Zip extension incorrectly\nhandled certain malformed Zip archives. A remote attacker could use this\nissue to cause PHP to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2016-3078)\n\nIt was discovered that PHP incorrectly handled invalid indexes in the\nSplDoublyLinkedList class. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3132)\n\nIt was discovered that the PHP rawurlencode() function incorrectly handled\nlarge strings. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS. (CVE-2016-4070)\n\nIt was discovered that the PHP php_snmp_error() function incorrectly\nhandled string formatting. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4071)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\nfilenames in archives. A remote attacker could use this issue to cause PHP\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4072)\n\nIt was discovered that the PHP mb_strcut() function incorrectly handled\nstring formatting. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4073)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\narchive files. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and\nUbuntu 15.10. (CVE-2016-4342, CVE-2016-4343)\n\nIt was discovered that the PHP bcpowmod() function incorrectly handled\nmemory. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code. \n(CVE-2016-4537, CVE-2016-4538)\n\nIt was discovered that the PHP XML parser incorrectly handled certain\nmalformed XML data. A remote attacker could possibly use this issue to\ncause PHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4539)\n\nIt was discovered that certain PHP grapheme functions incorrectly handled\nnegative offsets. A remote attacker could possibly use this issue to cause\nPHP to crash, resulting in a denial of service. (CVE-2016-4540,\nCVE-2016-4541)\n\nIt was discovered that PHP incorrectly handled certain malformed EXIF tags.\nA remote attacker could possibly use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2016-4542, CVE-2016-4543,\nCVE-2016-4544)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.23","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"}],"wily":[{"name":"php5","version":"5.6.11+dfsg-1ubuntu3.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cgi","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cli","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-fpm","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"}],"xenial":[{"name":"php7.0","version":"7.0.4-7ubuntu2.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"libphp7.0-embed","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bcmath","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bz2","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cgi","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cli","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-common","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-curl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-dev","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-enchant","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-fpm","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gd","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-imap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-interbase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-intl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-json","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-ldap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mbstring","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mcrypt","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mysql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-odbc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-opcache","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pgsql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-phpdbg","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pspell","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-readline","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-recode","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-snmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-soap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sqlite3","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sybase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-tidy","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xml","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xmlrpc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xsl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-zip","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8865","CVE-2016-3078","CVE-2016-3132","CVE-2016-4070","CVE-2016-4071","CVE-2016-4072","CVE-2016-4073","CVE-2016-4342","CVE-2016-4343","CVE-2016-4537","CVE-2016-4538","CVE-2016-4539","CVE-2016-4540","CVE-2016-4541","CVE-2016-4542","CVE-2016-4543","CVE-2016-4544"]}]},{"id":"CVE-2016-4070","published":"2016-04-25T00:00:00","updated_at":"2025-08-04T19:24:34.503169+00:00","description":"\nInteger overflow in the php_raw_url_encode function in ext/standard/url.c\nin PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows\nremote attackers to cause a denial of service (application crash) via a\nlong string to the rawurlencode function. NOTE: the vendor says \"Not sure\nif this qualifies as security issue (probably not).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/04/11/7","https://ubuntu.com/security/notices/USN-2952-1","https://ubuntu.com/security/notices/USN-2984-1","https://www.cve.org/CVERecord?id=CVE-2016-4070"],"bugs":["https://bugs.php.net/bug.php?id=71798"],"patches":{"php5":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=95433e8e339dbb6b5d5541473c1661db6ba2c451"],"php7.0":["upstream: https://git.php.net/?p=php-src.git;a=commit;h=95433e8e339dbb6b5d5541473c1661db6ba2c451"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.22","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.20+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"5.6.11+dfsg-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.5-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.0.4-7ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2984-1"],"notices":[{"id":"USN-2984-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-05-24T17:31:16.121794","description":"It was discovered that the PHP Fileinfo component incorrectly handled\ncertain magic files. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)\n\nHans Jerry Illikainen discovered that the PHP Zip extension incorrectly\nhandled certain malformed Zip archives. A remote attacker could use this\nissue to cause PHP to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2016-3078)\n\nIt was discovered that PHP incorrectly handled invalid indexes in the\nSplDoublyLinkedList class. An attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3132)\n\nIt was discovered that the PHP rawurlencode() function incorrectly handled\nlarge strings. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS. (CVE-2016-4070)\n\nIt was discovered that the PHP php_snmp_error() function incorrectly\nhandled string formatting. A remote attacker could use this issue to cause\nPHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4071)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\nfilenames in archives. A remote attacker could use this issue to cause PHP\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4072)\n\nIt was discovered that the PHP mb_strcut() function incorrectly handled\nstring formatting. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4073)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\narchive files. A remote attacker could use this issue to cause PHP to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and\nUbuntu 15.10. (CVE-2016-4342, CVE-2016-4343)\n\nIt was discovered that the PHP bcpowmod() function incorrectly handled\nmemory. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code. \n(CVE-2016-4537, CVE-2016-4538)\n\nIt was discovered that the PHP XML parser incorrectly handled certain\nmalformed XML data. A remote attacker could possibly use this issue to\ncause PHP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4539)\n\nIt was discovered that certain PHP grapheme functions incorrectly handled\nnegative offsets. A remote attacker could possibly use this issue to cause\nPHP to crash, resulting in a denial of service. (CVE-2016-4540,\nCVE-2016-4541)\n\nIt was discovered that PHP incorrectly handled certain malformed EXIF tags.\nA remote attacker could possibly use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2016-4542, CVE-2016-4543,\nCVE-2016-4544)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.23","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17","pocket":"security"}],"wily":[{"name":"php5","version":"5.6.11+dfsg-1ubuntu3.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cgi","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-cli","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"},{"name":"php5-fpm","version":"5.6.11+dfsg-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4"}],"xenial":[{"name":"php7.0","version":"7.0.4-7ubuntu2.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"libphp7.0-embed","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bcmath","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-bz2","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cgi","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-cli","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-common","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-curl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-dev","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-enchant","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-fpm","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gd","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-gmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-imap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-interbase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-intl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-json","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-ldap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mbstring","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mcrypt","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-mysql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-odbc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-opcache","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pgsql","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-phpdbg","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-pspell","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-readline","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-recode","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-snmp","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-soap","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sqlite3","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-sybase","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-tidy","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xml","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xmlrpc","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-xsl","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"},{"name":"php7.0-zip","version":"7.0.4-7ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php7.0","version_link":"https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8865","CVE-2016-3078","CVE-2016-3132","CVE-2016-4070","CVE-2016-4071","CVE-2016-4072","CVE-2016-4073","CVE-2016-4342","CVE-2016-4343","CVE-2016-4537","CVE-2016-4538","CVE-2016-4539","CVE-2016-4540","CVE-2016-4541","CVE-2016-4542","CVE-2016-4543","CVE-2016-4544"]}]},{"id":"CVE-2016-4054","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T22:02:08.342821+00:00","description":"\nBuffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows\nremote attackers to execute arbitrary code via crafted Edge Side Includes\n(ESI) responses.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same patches as CVE-2016-4052"}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=146116724827962&w=2","https://ubuntu.com/security/notices/USN-2995-1","https://www.cve.org/CVERecord?id=CVE-2016-4054"],"bugs":[""],"patches":{"squid3":[]},"tags":{},"packages":[{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"precise","status":"released","description":"3.1.19-1ubuntu3.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.3.8-1ubuntu6.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.17-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.3.8-1ubuntu16.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.12-1ubuntu7.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2995-1"],"notices":[{"id":"USN-2995-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-06-09T17:10:37.434388","description":"Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly\nhandled certain ICMPv6 packets. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly cause\nSquid to leak information into log files. (CVE-2016-3947)\n\nYuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly\nhandled certain crafted data. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4051)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4052, CVE-2016-4053, CVE-2016-4054)\n\nJianjun Chen discovered that Squid did not correctly ignore the Host header\nwhen absolute-URI is provided. A remote attacker could possibly use this\nissue to conduct cache-poisoning attacks. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. (CVE-2016-4553)\n\nJianjun Chen discovered that Squid incorrectly handled certain HTTP Host\nheaders. A remote attacker could possibly use this issue to conduct\ncache-poisoning attacks. (CVE-2016-4554)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2016-4555,\nCVE-2016-4556)\n","is_hidden":false,"release_packages":{"precise":[{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"},{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"}],"trusty":[{"name":"squid3","version":"3.3.8-1ubuntu6.8","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-cgi","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-purge","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3-common","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squidclient","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"}],"wily":[{"name":"squid3","version":"3.3.8-1ubuntu16.3","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"},{"name":"squid3","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"}],"xenial":[{"name":"squid3","version":"3.5.12-1ubuntu7.2","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-cgi","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-common","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-purge","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid3","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squidclient","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-3947","CVE-2016-4051","CVE-2016-4052","CVE-2016-4053","CVE-2016-4054","CVE-2016-4553","CVE-2016-4554","CVE-2016-4555","CVE-2016-4556"]}]},{"id":"CVE-2016-4053","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T22:02:08.342821+00:00","description":"\nSquid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to\nobtain sensitive stack layout information via crafted Edge Side Includes\n(ESI) responses, related to incorrect use of assert and compiler\noptimization.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same patches as CVE-2016-4052"}],"codename":null,"priority":"low","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=146116724827962&w=2","https://ubuntu.com/security/notices/USN-2995-1","https://www.cve.org/CVERecord?id=CVE-2016-4053"],"bugs":[""],"patches":{"squid3":[]},"tags":{},"packages":[{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"precise","status":"released","description":"3.1.19-1ubuntu3.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.3.8-1ubuntu6.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.17-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.3.8-1ubuntu16.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.12-1ubuntu7.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2995-1"],"notices":[{"id":"USN-2995-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-06-09T17:10:37.434388","description":"Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly\nhandled certain ICMPv6 packets. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly cause\nSquid to leak information into log files. (CVE-2016-3947)\n\nYuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly\nhandled certain crafted data. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4051)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4052, CVE-2016-4053, CVE-2016-4054)\n\nJianjun Chen discovered that Squid did not correctly ignore the Host header\nwhen absolute-URI is provided. A remote attacker could possibly use this\nissue to conduct cache-poisoning attacks. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. (CVE-2016-4553)\n\nJianjun Chen discovered that Squid incorrectly handled certain HTTP Host\nheaders. A remote attacker could possibly use this issue to conduct\ncache-poisoning attacks. (CVE-2016-4554)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2016-4555,\nCVE-2016-4556)\n","is_hidden":false,"release_packages":{"precise":[{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"},{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"}],"trusty":[{"name":"squid3","version":"3.3.8-1ubuntu6.8","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-cgi","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-purge","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3-common","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squidclient","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"}],"wily":[{"name":"squid3","version":"3.3.8-1ubuntu16.3","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"},{"name":"squid3","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"}],"xenial":[{"name":"squid3","version":"3.5.12-1ubuntu7.2","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-cgi","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-common","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-purge","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid3","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squidclient","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-3947","CVE-2016-4051","CVE-2016-4052","CVE-2016-4053","CVE-2016-4054","CVE-2016-4553","CVE-2016-4554","CVE-2016-4555","CVE-2016-4556"]}]},{"id":"CVE-2016-4052","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T22:02:08.342821+00:00","description":"\nMultiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x\nbefore 4.0.9 allow remote HTTP servers to cause a denial of service or\nexecute arbitrary code via crafted Edge Side Includes (ESI) responses.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=146116724827962&w=2","http://www.squid-cache.org/Advisories/SQUID-2016_6.txt","https://ubuntu.com/security/notices/USN-2995-1","https://www.cve.org/CVERecord?id=CVE-2016-4052"],"bugs":[""],"patches":{"squid3":["upstream: http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11841.patch","upstream: http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12697.patch","upstream: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14034.patch"]},"tags":{},"packages":[{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"precise","status":"released","description":"3.1.19-1ubuntu3.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.3.8-1ubuntu6.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.17-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.3.8-1ubuntu16.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.12-1ubuntu7.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2995-1"],"notices":[{"id":"USN-2995-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-06-09T17:10:37.434388","description":"Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly\nhandled certain ICMPv6 packets. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly cause\nSquid to leak information into log files. (CVE-2016-3947)\n\nYuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly\nhandled certain crafted data. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4051)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4052, CVE-2016-4053, CVE-2016-4054)\n\nJianjun Chen discovered that Squid did not correctly ignore the Host header\nwhen absolute-URI is provided. A remote attacker could possibly use this\nissue to conduct cache-poisoning attacks. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. (CVE-2016-4553)\n\nJianjun Chen discovered that Squid incorrectly handled certain HTTP Host\nheaders. A remote attacker could possibly use this issue to conduct\ncache-poisoning attacks. (CVE-2016-4554)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2016-4555,\nCVE-2016-4556)\n","is_hidden":false,"release_packages":{"precise":[{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"},{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"}],"trusty":[{"name":"squid3","version":"3.3.8-1ubuntu6.8","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-cgi","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-purge","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3-common","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squidclient","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"}],"wily":[{"name":"squid3","version":"3.3.8-1ubuntu16.3","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"},{"name":"squid3","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"}],"xenial":[{"name":"squid3","version":"3.5.12-1ubuntu7.2","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-cgi","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-common","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-purge","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid3","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squidclient","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-3947","CVE-2016-4051","CVE-2016-4052","CVE-2016-4053","CVE-2016-4054","CVE-2016-4553","CVE-2016-4554","CVE-2016-4555","CVE-2016-4556"]}]},{"id":"CVE-2016-4051","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T22:02:08.342821+00:00","description":"\nBuffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x\nbefore 4.0.9 might allow remote attackers to cause a denial of service or\nexecute arbitrary code by seeding manager reports with crafted data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.squid-cache.org/Advisories/SQUID-2016_5.txt","https://marc.info/?l=oss-security&m=146116724827962&w=2","https://ubuntu.com/security/notices/USN-2995-1","https://www.cve.org/CVERecord?id=CVE-2016-4051"],"bugs":[""],"patches":{"squid3":["upstream: http://www.squid-cache.org/Versions/v3/3.2/changesets/SQUID-2016_5.patch","upstream: http://www.squid-cache.org/Versions/v3/3.3/changesets/SQUID-2016_5.patch","upstream: http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_5.patch"]},"tags":{},"packages":[{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"precise","status":"released","description":"3.1.19-1ubuntu3.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.3.8-1ubuntu6.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.17-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.3.8-1ubuntu16.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.12-1ubuntu7.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2995-1"],"notices":[{"id":"USN-2995-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-06-09T17:10:37.434388","description":"Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly\nhandled certain ICMPv6 packets. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly cause\nSquid to leak information into log files. (CVE-2016-3947)\n\nYuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly\nhandled certain crafted data. A remote attacker could use this issue to\ncause Squid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4051)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2016-4052, CVE-2016-4053, CVE-2016-4054)\n\nJianjun Chen discovered that Squid did not correctly ignore the Host header\nwhen absolute-URI is provided. A remote attacker could possibly use this\nissue to conduct cache-poisoning attacks. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 15.10 and Ubuntu 16.04 LTS. (CVE-2016-4553)\n\nJianjun Chen discovered that Squid incorrectly handled certain HTTP Host\nheaders. A remote attacker could possibly use this issue to conduct\ncache-poisoning attacks. (CVE-2016-4554)\n\nIt was discovered that Squid incorrectly handled certain Edge Side Includes\n(ESI) responses. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2016-4555,\nCVE-2016-4556)\n","is_hidden":false,"release_packages":{"precise":[{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"},{"name":"squid3","version":"3.1.19-1ubuntu3.12.04.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.1.19-1ubuntu3.12.04.7"}],"trusty":[{"name":"squid3","version":"3.3.8-1ubuntu6.8","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-cgi","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid-purge","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squid3-common","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"},{"name":"squidclient","version":"3.3.8-1ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu6.8","pocket":"security"}],"wily":[{"name":"squid3","version":"3.3.8-1ubuntu16.3","description":"Web proxy cache server","is_source":true},{"name":"squid-cgi","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"},{"name":"squid3","version":"3.3.8-1ubuntu16.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.3.8-1ubuntu16.3"}],"xenial":[{"name":"squid3","version":"3.5.12-1ubuntu7.2","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-cgi","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-common","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid-purge","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squid3","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"},{"name":"squidclient","version":"3.5.12-1ubuntu7.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-3947","CVE-2016-4051","CVE-2016-4052","CVE-2016-4053","CVE-2016-4054","CVE-2016-4553","CVE-2016-4554","CVE-2016-4555","CVE-2016-4556"]}]},{"id":"CVE-2016-2109","published":"2016-04-25T00:00:00","updated_at":"2025-08-25T21:56:31.525317+00:00","description":"\nThe asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO\nimplementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows\nremote attackers to cause a denial of service (memory consumption) via a\nshort invalid encoding.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openssl.org/news/secadv/20160503.txt","https://ubuntu.com/security/notices/USN-2959-1","https://www.cve.org/CVERecord?id=CVE-2016-2109"],"bugs":[""],"patches":{"openssl":["upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=c62981390d6cf9e3d612c489b8b77c2913b25807","upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=9f13d4dd5ec420fb2fa0a7b94a6d66bb2700a492 (test)"],"openssl098":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"artful","status":"released","description":"1.0.2g-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2g-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.0.2g-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1.0.2g-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.0.1-4ubuntu5.36","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1f-1ubuntu2.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.1t, 1.0.2h","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.0.2d-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.2g-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.0.2g-1ubuntu5","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.0.2g-1ubuntu5","component":null,"pocket":"security"}]},{"name":"openssl098","source":"https://ubuntu.com/security/cve?package=openssl098","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl098","debian":"https://tracker.debian.org/pkg/openssl098","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-2959-1"],"notices":[{"id":"USN-2959-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2016-05-03T14:49:08.869474","description":"Huzaifa Sidhpurwala, Hanno Böck, and David Benjamin discovered that OpenSSL\nincorrectly handled memory when decoding ASN.1 structures. A remote\nattacker could use this issue to cause OpenSSL to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-2108)\n\nJuraj Somorovsky discovered that OpenSSL incorrectly performed padding when\nthe connection uses the AES CBC cipher and the server supports AES-NI. A\nremote attacker could possibly use this issue to perform a padding oracle\nattack and decrypt traffic. (CVE-2016-2107)\n\nGuido Vranken discovered that OpenSSL incorrectly handled large amounts of\ninput data to the EVP_EncodeUpdate() function. A remote attacker could use\nthis issue to cause OpenSSL to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2016-2105)\n\nGuido Vranken discovered that OpenSSL incorrectly handled large amounts of\ninput data to the EVP_EncryptUpdate() function. A remote attacker could use\nthis issue to cause OpenSSL to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2016-2106)\n\nBrian Carpenter discovered that OpenSSL incorrectly handled memory when\nASN.1 data is read from a BIO. A remote attacker could possibly use this\nissue to cause memory consumption, resulting in a denial of service.\n(CVE-2016-2109)\n\nAs a security improvement, this update also modifies OpenSSL behaviour to\nreject DH key sizes below 1024 bits, preventing a possible downgrade\nattack.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openssl","version":"1.0.1-4ubuntu5.36","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.1-4ubuntu5.36","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.36"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.19","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libcrypto1.0.0-udeb","version":"1.0.1f-1ubuntu2.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.19","pocket":"security"},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.19","pocket":"security"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.19","pocket":"security"},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.19","pocket":"security"},{"name":"libssl1.0.0-udeb","version":"1.0.1f-1ubuntu2.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.19","pocket":"security"},{"name":"openssl","version":"1.0.1f-1ubuntu2.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.19","pocket":"security"}],"wily":[{"name":"openssl","version":"1.0.2d-0ubuntu1.5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.2d-0ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2d-0ubuntu1.5"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.1","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libcrypto1.0.0-udeb","version":"1.0.2g-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.1","pocket":"security"},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.1","pocket":"security"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.1","pocket":"security"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.1","pocket":"security"},{"name":"libssl1.0.0-udeb","version":"1.0.2g-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.1","pocket":"security"},{"name":"openssl","version":"1.0.2g-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-2105","CVE-2016-2106","CVE-2016-2107","CVE-2016-2108","CVE-2016-2109"]}]},{"id":"CVE-2015-8823","published":"2016-04-22T18:59:00","updated_at":"2025-08-25T21:49:26.349855+00:00","description":"\nUse-after-free vulnerability in the TextField object implementation in\nAdobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on\nWindows and OS X and before 11.2.202.554 on Linux, Adobe AIR before\n20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler\nbefore 20.0.0.204 allows attackers to execute arbitrary code via crafted\ntext property, a different vulnerability than CVE-2015-8048, CVE-2015-8049,\nCVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058,\nCVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064,\nCVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069,\nCVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403,\nCVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411,\nCVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421,\nCVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426,\nCVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430, CVE-2015-8431,\nCVE-2015-8432, CVE-2015-8433, CVE-2015-8434, CVE-2015-8435, CVE-2015-8436,\nCVE-2015-8437, CVE-2015-8441, CVE-2015-8442, CVE-2015-8447, CVE-2015-8448,\nCVE-2015-8449, CVE-2015-8450, CVE-2015-8452, CVE-2015-8454, CVE-2015-8653,\nCVE-2015-8655, CVE-2015-8821, and CVE-2015-8822.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://helpx.adobe.com/security/products/flash-player/apsb15-32.html","http://www.zerodayinitiative.com/advisories/ZDI-15-665","https://www.cve.org/CVERecord?id=CVE-2015-8823"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.554","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3190","published":"2016-04-21T14:59:00","updated_at":"2025-08-25T21:59:31.081606+00:00","description":"\nThe fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in\ncairo before 1.14.2 allows remote attackers to cause a denial of service\n(out-of-bounds read and application crash) via a negative span length.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Fixed in 1.14.2"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://mail.gnome.org/archives/gnome-announce-list/2015-March/msg00047.html","https://www.cve.org/CVERecord?id=CVE-2016-3190"],"bugs":[""],"patches":{"cairo":["upstream: https://cgit.freedesktop.org/cairo/patch/src/cairo-image-compositor.c?id=5c82d91a5e15d29b1489dcb413b24ee7fdf59934"]},"tags":{},"packages":[{"name":"cairo","source":"https://ubuntu.com/security/cve?package=cairo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cairo","debian":"https://tracker.debian.org/pkg/cairo","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.14.2-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.14.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7449","published":"2016-04-21T14:59:00","updated_at":"2025-08-25T21:08:27.832508+00:00","description":"\nThe ssl_do_connect function in common/server.c in HexChat before 2.10.2,\nXChat, and XChat-GNOME does not verify that the server hostname matches a\ndomain name in the X.509 certificate, which allows man-in-the-middle\nattackers to spoof SSL servers via an arbitrary valid certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2016/q2/17","http://seclists.org/oss-sec/2015/q1/342","https://github.com/hexchat/hexchat/issues/524","https://launchpad.net/bugs/1565000","https://bugzilla.redhat.com/show_bug.cgi?id=1081839","https://www.cve.org/CVERecord?id=CVE-2013-7449"],"bugs":[""],"patches":{"xchat":[],"hexchat":["upstream: https://github.com/hexchat/hexchat/commit/c9b63f7f9be01692b03fa15275135a4910a7e02d","upstream: https://github.com/hexchat/hexchat/commit/50463ca8321c39f3966c278ab25ca158404d72f1"],"xchat-gnome":[]},"tags":{},"packages":[{"name":"hexchat","source":"https://ubuntu.com/security/cve?package=hexchat","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hexchat","debian":"https://tracker.debian.org/pkg/hexchat","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.9.6.1-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.10.2-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.10.2-1ubuntu2","component":null,"pocket":"security"}]},{"name":"xchat","source":"https://ubuntu.com/security/cve?package=xchat","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xchat","debian":"https://tracker.debian.org/pkg/xchat","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.8.8-10","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.8.8-10","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.8.8-10","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.8.8-10","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"xchat-gnome","source":"https://ubuntu.com/security/cve?package=xchat-gnome","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xchat-gnome","debian":"https://tracker.debian.org/pkg/xchat-gnome","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:0.30.0~git20141005.816798-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:0.30.0~git20110821.e2a400-0.2ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:0.30.0~git20131003.d20b8d+really20110821-0.2ubuntu12.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:0.30.0~git20141005.816798-0ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:0.30.0~git20141005.816798-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3449","published":"2016-04-21T11:00:00","updated_at":"2025-08-25T21:59:35.417361+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows\nremote attackers to affect confidentiality, integrity, and availability via\nvectors related to Deployment.","ubuntu_description":"\nA vulnerability was discovered in the OpenJDK JRE related\nto information disclosure, data integrity, and availability. An\nattacker could exploit these to cause a denial of service, expose\nsensitive data over the network, or possibly execute arbitrary code.","notes":[{"author":"sbeattie","note":"java deployment, does not affect openjdk as packaged"}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html#AppendixJAVA","https://www.cve.org/CVERecord?id=CVE-2016-3449"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-8":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"precise","status":"not-affected","description":"deployment","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"deployment","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [deployment]","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"precise","status":"not-affected","description":"deployment","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"deployment","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [deployment]","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"deployment","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"deployment","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3443","published":"2016-04-21T11:00:00","updated_at":"2025-08-25T21:59:35.417361+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows\nremote attackers to affect confidentiality, integrity, and availability via\nvectors related to 2D. NOTE: the previous information is from the April\n2016 CPU. Oracle has not commented on third-party claims that this issue\nallows remote attackers to obtain sensitive information via crafted font\ndata, which triggers an out-of-bounds read.","ubuntu_description":"\nA vulnerability was discovered in the OpenJDK JRE related\nto information disclosure, data integrity, and availability. An\nattacker could exploit these to cause a denial of service, expose\nsensitive data over the network, or possibly execute arbitrary code.","notes":[{"author":"sbeattie","note":"Specific to Oracle Java, not present in IcedTea"}],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html#AppendixJAVA","https://www.cve.org/CVERecord?id=CVE-2016-3443"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-8":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"precise","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"precise","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [oracle only]","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"oracle only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"oracle only","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":61060,"limit":20,"total_results":79316}