{"cves":[{"id":"CVE-2015-8718","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:47.858020+00:00","description":"\nDouble free vulnerability in epan/dissectors/packet-nlm.c in the NLM\ndissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1, when\nthe \"Match MSG/RES packets for async NLM\" option is enabled, allows remote\nattackers to cause a denial of service (application crash) via a crafted\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=81dfe6d450ada42d12f20ac26a6d8ae2302df37e","http://www.wireshark.org/security/wnpa-sec-2015-37.html","https://www.cve.org/CVERecord?id=CVE-2015-8718"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8717","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:47.858020+00:00","description":"\nThe dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP\ndissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a\nnegative media count, which allows remote attackers to cause a denial of\nservice (application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=2ddd92b6f8f587325b9e14598658626f3a007c5c","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9887","http://www.wireshark.org/security/wnpa-sec-2015-36.html","https://www.cve.org/CVERecord?id=CVE-2015-8717"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.0.2+ga16e22e-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8716","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:47.858020+00:00","description":"\nThe init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38\ndissector in Wireshark 1.12.x before 1.12.9 does not ensure that a\nconversation exists, which allows remote attackers to cause a denial of\nservice (application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=eb6ccb1b0c4ad02b828652c3fe6e8d51c30a315e","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9887","http://www.wireshark.org/security/wnpa-sec-2015-35.html","https://www.cve.org/CVERecord?id=CVE-2015-8716"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.2.6+g32dac6a-2ubuntu0.16.04","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8715","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:47.858020+00:00","description":"\nepan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark\n1.12.x before 1.12.9 does not check for empty arguments, which allows\nremote attackers to cause a denial of service (infinite loop) via a crafted\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=40caff2d1fb08262c84aaaa8ac584baa8866dd7c","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11607","http://www.wireshark.org/security/wnpa-sec-2015-34.html","https://www.cve.org/CVERecord?id=CVE-2015-8715"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.0.2+ga16e22e-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8714","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:43.108828+00:00","description":"\nThe dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the\nDCOM dissector in Wireshark 1.12.x before 1.12.9 does not initialize a\ncertain IPv4 data structure, which allows remote attackers to cause a\ndenial of service (application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=d34267d0503a67235bf259fd2f2f2d2bb8b18cf5","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11610","http://www.wireshark.org/security/wnpa-sec-2015-33.html","https://www.cve.org/CVERecord?id=CVE-2015-8714"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.0.2+ga16e22e-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8713","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:43.108828+00:00","description":"\nepan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark\n1.12.x before 1.12.9 does not properly reserve memory for channel ID\nmappings, which allows remote attackers to cause a denial of service\n(out-of-bounds memory access and application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=67b6d4f7e6f2117b40957fd51518aa2a3e659002","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11606","http://www.wireshark.org/security/wnpa-sec-2015-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8713"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.0.2+ga16e22e-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8712","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:43.108828+00:00","description":"\nThe dissect_hsdsch_channel_info function in\nepan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark\n1.12.x before 1.12.9 does not validate the number of PDUs, which allows\nremote attackers to cause a denial of service (application crash) via a\ncrafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=2ae329a47b7f0ac94089c23e79c6b8bc18ba80ea","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11602","http://www.wireshark.org/security/wnpa-sec-2015-32.html","https://www.cve.org/CVERecord?id=CVE-2015-8712"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.0.2+ga16e22e-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8711","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:48:43.108828+00:00","description":"\nepan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x\nbefore 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data,\nwhich allows remote attackers to cause a denial of service (NULL pointer\ndereference and application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=5bf565690ad9f0771196d8fa237aa37fae3bb7cc","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=5b4ada17723ed8af7e85cb48d537437ed614e417","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=23379ae3624df82c170f48e5bb3250a97ec61c13","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11841","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11835","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11602","http://www.wireshark.org/security/wnpa-sec-2015-31.html","https://www.cve.org/CVERecord?id=CVE-2015-8711"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12.1+g01b65bf-4+deb8u11ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3182","published":"2016-01-04T05:59:00","updated_at":"2025-08-25T21:37:46.036983+00:00","description":"\nepan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in\nWireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value,\nwhich allows remote attackers to cause a denial of service (application\ncrash) via a crafted packet.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"wireshark 1.10 only according to RH bug"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1219409","https://www.cve.org/CVERecord?id=CVE-2015-3182"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.10 only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.10 only","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.10 only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.10 only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.10 only","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.10 only","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8745","published":"2016-01-04T00:00:00","updated_at":"2025-08-25T21:49:02.362164+00:00","description":"\nQEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC\nemulator support is vulnerable to crash issue. It could occur while reading\nInterrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user\ncould use this flaw to crash the QEMU process instance resulting in DoS.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/01/04/4","https://ubuntu.com/security/notices/USN-2891-1","https://www.cve.org/CVERecord?id=CVE-2015-8745"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1270876"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=c6048f849c7e3f009786df76206e895"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.22","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:2.3+dfsg-5ubuntu9.2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2891-1"],"notices":[{"id":"USN-2891-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2016-02-03T13:07:20.004708","description":"Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-7549)\n\nLian Yihan discovered that QEMU incorrectly handled the VNC server. A\nremote attacker could use this issue to cause QEMU to crash, resulting in a\ndenial of service. (CVE-2015-8504)\n\nFelix Wilhelm discovered a race condition in the Xen paravirtualized\ndrivers which can cause double fetch vulnerabilities. An attacker in the\nparavirtualized guest could exploit this flaw to cause a denial of service\n(crash the host) or potentially execute arbitrary code on the host.\n(CVE-2015-8550)\n\nQinghao Tang discovered that QEMU incorrectly handled USB EHCI emulation\nsupport. An attacker inside the guest could use this issue to cause QEMU to\nconsume resources, resulting in a denial of service. (CVE-2015-8558)\n\nQinghao Tang discovered that QEMU incorrectly handled the vmxnet3 device.\nAn attacker inside the guest could use this issue to cause QEMU to consume\nresources, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8567, CVE-2015-8568)\n\nQinghao Tang discovered that QEMU incorrectly handled SCSI MegaRAID SAS HBA\nemulation. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8613)\n\nLing Liu discovered that QEMU incorrectly handled the Human Monitor\nInterface. A local attacker could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-8619, CVE-2016-1922)\n\nDavid Alan Gilbert discovered that QEMU incorrectly handled the Q35 chipset\nemulation when performing VM guest migrations. An attacker could use this\nissue to cause QEMU to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8666)\n\nLing Liu discovered that QEMU incorrectly handled the NE2000 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2015-8743)\n\nIt was discovered that QEMU incorrectly handled the vmxnet3 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-8744, CVE-2015-8745)\n\nQinghao Tang discovered that QEMU incorrect handled IDE AHCI emulation. An\nattacker inside the guest could use this issue to cause a denial of\nservice, or possibly execute arbitrary code on the host as the user running\nthe QEMU process. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2016-1568)\n\nDonghai Zhu discovered that QEMU incorrect handled the firmware\nconfiguration device. An attacker inside the guest could use this issue to\ncause a denial of service, or possibly execute arbitrary code on the host\nas the user running the QEMU process. In the default installation, when\nQEMU is used with libvirt, attackers would be isolated by the libvirt\nAppArmor profile. (CVE-2016-1714)\n\nIt was discovered that QEMU incorrectly handled the e1000 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-1981)\n\nZuozhi Fzz discovered that QEMU incorrectly handled IDE AHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 15.10.\n(CVE-2016-2197)\n\nZuozhi Fzz discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2016-2198)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.27","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.27","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.27"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.22","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"}],"wily":[{"name":"qemu","version":"1:2.3+dfsg-5ubuntu9.2","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-aarch64","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-arm","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-mips","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-misc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-ppc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-sparc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-x86","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"}]},"type":"USN","cves_ids":["CVE-2015-7549","CVE-2015-8504","CVE-2015-8550","CVE-2015-8558","CVE-2015-8567","CVE-2015-8568","CVE-2015-8613","CVE-2015-8619","CVE-2015-8666","CVE-2015-8743","CVE-2015-8744","CVE-2015-8745","CVE-2016-1568","CVE-2016-1714","CVE-2016-1922","CVE-2016-1981","CVE-2016-2197","CVE-2016-2198"]}]},{"id":"CVE-2015-8744","published":"2016-01-04T00:00:00","updated_at":"2025-08-25T21:48:57.684344+00:00","description":"\nQEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC\nemulator support is vulnerable to crash issue. It occurs when a guest sends\na Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest\nuser could use this flaw to crash the QEMU process instance resulting in\nDoS.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/01/04/3","https://ubuntu.com/security/notices/USN-2891-1","https://www.cve.org/CVERecord?id=CVE-2015-8744"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1270871"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=a7278b36fcab9af469563bd7b"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.22","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:2.3+dfsg-5ubuntu9.2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2891-1"],"notices":[{"id":"USN-2891-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2016-02-03T13:07:20.004708","description":"Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-7549)\n\nLian Yihan discovered that QEMU incorrectly handled the VNC server. A\nremote attacker could use this issue to cause QEMU to crash, resulting in a\ndenial of service. (CVE-2015-8504)\n\nFelix Wilhelm discovered a race condition in the Xen paravirtualized\ndrivers which can cause double fetch vulnerabilities. An attacker in the\nparavirtualized guest could exploit this flaw to cause a denial of service\n(crash the host) or potentially execute arbitrary code on the host.\n(CVE-2015-8550)\n\nQinghao Tang discovered that QEMU incorrectly handled USB EHCI emulation\nsupport. An attacker inside the guest could use this issue to cause QEMU to\nconsume resources, resulting in a denial of service. (CVE-2015-8558)\n\nQinghao Tang discovered that QEMU incorrectly handled the vmxnet3 device.\nAn attacker inside the guest could use this issue to cause QEMU to consume\nresources, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8567, CVE-2015-8568)\n\nQinghao Tang discovered that QEMU incorrectly handled SCSI MegaRAID SAS HBA\nemulation. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8613)\n\nLing Liu discovered that QEMU incorrectly handled the Human Monitor\nInterface. A local attacker could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-8619, CVE-2016-1922)\n\nDavid Alan Gilbert discovered that QEMU incorrectly handled the Q35 chipset\nemulation when performing VM guest migrations. An attacker could use this\nissue to cause QEMU to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8666)\n\nLing Liu discovered that QEMU incorrectly handled the NE2000 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2015-8743)\n\nIt was discovered that QEMU incorrectly handled the vmxnet3 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-8744, CVE-2015-8745)\n\nQinghao Tang discovered that QEMU incorrect handled IDE AHCI emulation. An\nattacker inside the guest could use this issue to cause a denial of\nservice, or possibly execute arbitrary code on the host as the user running\nthe QEMU process. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2016-1568)\n\nDonghai Zhu discovered that QEMU incorrect handled the firmware\nconfiguration device. An attacker inside the guest could use this issue to\ncause a denial of service, or possibly execute arbitrary code on the host\nas the user running the QEMU process. In the default installation, when\nQEMU is used with libvirt, attackers would be isolated by the libvirt\nAppArmor profile. (CVE-2016-1714)\n\nIt was discovered that QEMU incorrectly handled the e1000 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-1981)\n\nZuozhi Fzz discovered that QEMU incorrectly handled IDE AHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 15.10.\n(CVE-2016-2197)\n\nZuozhi Fzz discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2016-2198)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.27","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.27","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.27"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.22","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"}],"wily":[{"name":"qemu","version":"1:2.3+dfsg-5ubuntu9.2","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-aarch64","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-arm","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-mips","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-misc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-ppc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-sparc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-x86","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"}]},"type":"USN","cves_ids":["CVE-2015-7549","CVE-2015-8504","CVE-2015-8550","CVE-2015-8558","CVE-2015-8567","CVE-2015-8568","CVE-2015-8613","CVE-2015-8619","CVE-2015-8666","CVE-2015-8743","CVE-2015-8744","CVE-2015-8745","CVE-2016-1568","CVE-2016-1714","CVE-2016-1922","CVE-2016-1981","CVE-2016-2197","CVE-2016-2198"]}]},{"id":"CVE-2015-8743","published":"2016-01-04T00:00:00","updated_at":"2025-08-25T21:48:57.684344+00:00","description":"\nQEMU (aka Quick Emulator) built with the NE2000 device emulation support is\nvulnerable to an OOB r/w access issue. It could occur while performing\n'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could\nuse this flaw to leak or corrupt QEMU memory bytes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/01/04/1","https://ubuntu.com/security/notices/USN-2891-1","https://www.cve.org/CVERecord?id=CVE-2015-8743"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1264929"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=aa7f9966dfdff500bbbf1956d9e115b1fa8987a6"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.22","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:2.3+dfsg-5ubuntu9.2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2891-1"],"notices":[{"id":"USN-2891-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2016-02-03T13:07:20.004708","description":"Qinghao Tang discovered that QEMU incorrectly handled PCI MSI-X support. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-7549)\n\nLian Yihan discovered that QEMU incorrectly handled the VNC server. A\nremote attacker could use this issue to cause QEMU to crash, resulting in a\ndenial of service. (CVE-2015-8504)\n\nFelix Wilhelm discovered a race condition in the Xen paravirtualized\ndrivers which can cause double fetch vulnerabilities. An attacker in the\nparavirtualized guest could exploit this flaw to cause a denial of service\n(crash the host) or potentially execute arbitrary code on the host.\n(CVE-2015-8550)\n\nQinghao Tang discovered that QEMU incorrectly handled USB EHCI emulation\nsupport. An attacker inside the guest could use this issue to cause QEMU to\nconsume resources, resulting in a denial of service. (CVE-2015-8558)\n\nQinghao Tang discovered that QEMU incorrectly handled the vmxnet3 device.\nAn attacker inside the guest could use this issue to cause QEMU to consume\nresources, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8567, CVE-2015-8568)\n\nQinghao Tang discovered that QEMU incorrectly handled SCSI MegaRAID SAS HBA\nemulation. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8613)\n\nLing Liu discovered that QEMU incorrectly handled the Human Monitor\nInterface. A local attacker could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-8619, CVE-2016-1922)\n\nDavid Alan Gilbert discovered that QEMU incorrectly handled the Q35 chipset\nemulation when performing VM guest migrations. An attacker could use this\nissue to cause QEMU to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-8666)\n\nLing Liu discovered that QEMU incorrectly handled the NE2000 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2015-8743)\n\nIt was discovered that QEMU incorrectly handled the vmxnet3 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2015-8744, CVE-2015-8745)\n\nQinghao Tang discovered that QEMU incorrect handled IDE AHCI emulation. An\nattacker inside the guest could use this issue to cause a denial of\nservice, or possibly execute arbitrary code on the host as the user running\nthe QEMU process. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2016-1568)\n\nDonghai Zhu discovered that QEMU incorrect handled the firmware\nconfiguration device. An attacker inside the guest could use this issue to\ncause a denial of service, or possibly execute arbitrary code on the host\nas the user running the QEMU process. In the default installation, when\nQEMU is used with libvirt, attackers would be isolated by the libvirt\nAppArmor profile. (CVE-2016-1714)\n\nIt was discovered that QEMU incorrectly handled the e1000 device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-1981)\n\nZuozhi Fzz discovered that QEMU incorrectly handled IDE AHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 15.10.\n(CVE-2016-2197)\n\nZuozhi Fzz discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 15.10. (CVE-2016-2198)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.27","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.27","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.27"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.22","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.22","pocket":"security"}],"wily":[{"name":"qemu","version":"1:2.3+dfsg-5ubuntu9.2","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-aarch64","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-arm","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-mips","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-misc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-ppc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-sparc","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"},{"name":"qemu-system-x86","version":"1:2.3+dfsg-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.2"}]},"type":"USN","cves_ids":["CVE-2015-7549","CVE-2015-8504","CVE-2015-8550","CVE-2015-8558","CVE-2015-8567","CVE-2015-8568","CVE-2015-8613","CVE-2015-8619","CVE-2015-8666","CVE-2015-8743","CVE-2015-8744","CVE-2015-8745","CVE-2016-1568","CVE-2016-1714","CVE-2016-1922","CVE-2016-1981","CVE-2016-2197","CVE-2016-2198"]}]},{"id":"CVE-2015-8027","published":"2016-01-02T21:59:00","updated_at":"2025-08-25T21:46:46.691091+00:00","description":"\nNode.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does\nnot ensure the availability of a parser for each HTTP socket, which allows\nremote attackers to cause a denial of service (uncaughtException and\nservice outage) via a pipelined HTTP request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://nodejs.org/en/blog/vulnerability/cve-2015-8027_cve-2015-6764/","https://www.cve.org/CVERecord?id=CVE-2015-8027"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806385"],"patches":{"nodejs":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8.10.0~dfsg-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.3~dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.6~dfsg-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1283","published":"2016-01-02T00:00:00","updated_at":"2025-08-25T21:54:02.796315+00:00","description":"\nThe pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the\n/((?:F?+(?:^(?(R)a+\\\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\\){97)?J)?J)(?'R'(?'R'\\){99|(:(?|(?'R')(\\k'R')|((?'R')))H'R'R)(H'R))))))/\npattern and related patterns with named subgroups, which allows remote\nattackers to cause a denial of service (heap-based buffer overflow) or\npossibly have unspecified other impact via a crafted regular expression, as\ndemonstrated by a JavaScript RegExp object encountered by Konqueror.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 8.34"},{"author":"ebarretto","note":"pcre2 not affected as vulnerable code is not present"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://bugs.exim.org/show_bug.cgi?id=1767","https://ubuntu.com/security/notices/USN-2943-1","https://www.cve.org/CVERecord?id=CVE-2016-1283"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=809706","https://bugs.exim.org/show_bug.cgi?id=1767"],"patches":{"pcre3":["upstream: http://vcs.pcre.org/pcre?view=revision&revision=1636"],"pcre2":[]},"tags":{},"packages":[{"name":"pcre2","source":"https://ubuntu.com/security/cve?package=pcre2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre2","debian":"https://tracker.debian.org/pkg/pcre2","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"pcre3","source":"https://ubuntu.com/security/cve?package=pcre3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre3","debian":"https://tracker.debian.org/pkg/pcre3","statuses":[{"release_codename":"artful","status":"not-affected","description":"2:8.38-3.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2:8.38-3.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2:8.38-3.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1:8.31-2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:8.38-3.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2:8.35-7.1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:8.38-3.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2:8.38-3.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2:8.38-3.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2943-1"],"notices":[{"id":"USN-2943-1","title":"PCRE vulnerabilities","summary":"PCRE could be made to crash or run programs if it processed a\nspecially-crafted regular expression.\n","instructions":"After a standard system update you need to restart applications using PCRE,\nsuch as the Apache HTTP server and Nginx, to make all the necessary\nchanges.\n","references":[],"published":"2016-03-29T17:10:38.277860","description":"It was discovered that PCRE incorrectly handled certain regular\nexpressions. A remote attacker could use this issue to cause applications\nusing PCRE to crash, resulting in a denial of service, or possibly execute\narbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"pcre3","version":"8.12-4ubuntu0.2","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"libpcre3","version":"8.12-4ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/8.12-4ubuntu0.2"}],"trusty":[{"name":"pcre3","version":"1:8.31-2ubuntu2.2","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"libpcre3","version":"1:8.31-2ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2","pocket":"security"},{"name":"libpcre3-dev","version":"1:8.31-2ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2","pocket":"security"},{"name":"libpcre3-udeb","version":"1:8.31-2ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2","pocket":"security"},{"name":"libpcrecpp0","version":"1:8.31-2ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2","pocket":"security"},{"name":"pcregrep","version":"1:8.31-2ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/1:8.31-2ubuntu2.2","pocket":"security"}],"wily":[{"name":"pcre3","version":"2:8.35-7.1ubuntu1.3","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"libpcre3","version":"2:8.35-7.1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.35-7.1ubuntu1.3"}]},"type":"USN","cves_ids":["CVE-2014-9769","CVE-2015-2325","CVE-2015-2326","CVE-2015-2327","CVE-2015-2328","CVE-2015-3210","CVE-2015-5073","CVE-2015-8380","CVE-2015-8381","CVE-2015-8382","CVE-2015-8383","CVE-2015-8384","CVE-2015-8385","CVE-2015-8386","CVE-2015-8387","CVE-2015-8388","CVE-2015-8389","CVE-2015-8390","CVE-2015-8391","CVE-2015-8392","CVE-2015-8393","CVE-2015-8394","CVE-2015-8395","CVE-2016-1283","CVE-2016-3191"]}]},{"id":"CVE-2015-9542","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:30.116843+00:00","description":"\nadd_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly\ncheck the length of the input password, and is vulnerable to a stack-based\nbuffer overflow during memcpy(). An attacker could send a crafted password\nto an application (loading the pam_radius library) and crash it. Arbitrary\ncode execution might be possible, depending on the application, C library,\ncompiler, and other factors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4290-1","https://ubuntu.com/security/notices/USN-4290-2","https://www.cve.org/CVERecord?id=CVE-2015-9542"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=951396","https://bugzilla.redhat.com/show_bug.cgi?id=1686980"],"patches":{"libpam-radius-auth":["upstream: https://github.com/FreeRADIUS/pam_radius/commit/01173ec","upstream: https://github.com/FreeRADIUS/pam_radius/commit/6bae92d","upstream: https://github.com/FreeRADIUS/pam_radius/commit/ac2c1677"]},"tags":{},"packages":[{"name":"libpam-radius-auth","source":"https://ubuntu.com/security/cve?package=libpam-radius-auth","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpam-radius-auth","debian":"https://tracker.debian.org/pkg/libpam-radius-auth","statuses":[{"release_codename":"bionic","status":"released","description":"1.3.17-0ubuntu5.18.04.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1.3.17-0ubuntu5.19.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.17-0ubuntu4+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.17-0ubuntu4.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4290-2","USN-4290-1"],"notices":[{"id":"USN-4290-2","title":"libpam-radius-auth vulnerability","summary":"libpam-radius-auth could be made to crash if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-03-03T11:54:46.188096","description":"USN-4290-1 fixed a vulnerability in libpam-radius-auth. This update provides\nthe corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that libpam-radius-auth incorrectly handled certain long\n passwords. A remote attacker could possibly use this issue to cause\n libpam-radius-auth to crash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"precise":[{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu3.1","description":"The PAM RADIUS authentication module","is_source":true},{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth","version_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth/1.3.17-0ubuntu3.1"}],"trusty":[{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu4+esm1","description":"The PAM RADIUS authentication module","is_source":true},{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu4+esm1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth","version_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth/1.3.17-0ubuntu4+esm1"}]},"type":"USN","cves_ids":["CVE-2015-9542"]},{"id":"USN-4290-1","title":"libpam-radius-auth vulnerability","summary":"libpam-radius-auth could be made to crash if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-02-24T14:21:20.157320","description":"It was discovered that libpam-radius-auth incorrectly handled certain long\npasswords. A remote attacker could possibly use this issue to cause\nlibpam-radius-auth to crash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu5.18.04.1","description":"The PAM RADIUS authentication module","is_source":true},{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu5.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth","version_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth/1.3.17-0ubuntu5.18.04.1","pocket":"security"}],"eoan":[{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu5.19.10.1","description":"The PAM RADIUS authentication module","is_source":true},{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu5.19.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth","version_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth/1.3.17-0ubuntu5.19.10.1"}],"xenial":[{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu4.1","description":"The PAM RADIUS authentication module","is_source":true},{"name":"libpam-radius-auth","version":"1.3.17-0ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth","version_link":"https://launchpad.net/ubuntu/+source/libpam-radius-auth/1.3.17-0ubuntu4.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-9542"]}]},{"id":"CVE-2015-8984","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:16.148927+00:00","description":"\nThe fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22\nmight allow context-dependent attackers to cause a denial of service\n(application crash) via a malformed pattern, which triggers an\nout-of-bounds read.","ubuntu_description":"\nIt was discovered that the fnmatch() function in the GNU C Library did\nnot properly handle certain malformed patterns. An attacker could use\nthis to cause a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=18032","https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=4a28f4d55a6cc33474c0792fe93b5942d81bf185","http://www.openwall.com/lists/oss-security/2015/02/26/5","https://ubuntu.com/security/notices/USN-3239-1","https://www.cve.org/CVERecord?id=CVE-2015-8984"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779587"],"patches":{"eglibc":[],"glibc":["upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=4a28f4d55a6cc33474c0792fe93b5942d81bf185"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.19-0ubuntu6.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3239-1"],"notices":[{"id":"USN-3239-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2017-03-21T02:58:45.626524","description":"It was discovered that the GNU C Library incorrectly handled the\nstrxfrm() function. An attacker could use this issue to cause a denial\nof service or possibly execute arbitrary code. This issue only affected\nUbuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)\n\nIt was discovered that an integer overflow existed in the\n_IO_wstr_overflow() function of the GNU C Library. An attacker could\nuse this to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04\nLTS. (CVE-2015-8983)\n\nIt was discovered that the fnmatch() function in the GNU C Library\ndid not properly handle certain malformed patterns. An attacker could\nuse this to cause a denial of service. This issue only affected Ubuntu\n12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8984)\n\nAlexander Cherepanov discovered a stack-based buffer overflow in the\nglob implementation of the GNU C Library. An attacker could use this\nto specially craft a directory layout and cause a denial of service.\n(CVE-2016-1234)\n\nFlorian Weimer discovered a NULL pointer dereference in the DNS\nresolver of the GNU C Library. An attacker could use this to cause\na denial of service. (CVE-2015-5180)\n\nMichael Petlan discovered an unbounded stack allocation in the\ngetaddrinfo() function of the GNU C Library. An attacker could use\nthis to cause a denial of service. (CVE-2016-3706)\n\nAldy Hernandez discovered an unbounded stack allocation in the sunrpc\nimplementation in the GNU C Library. An attacker could use this to\ncause a denial of service. (CVE-2016-4429)\n\nTim Ruehsen discovered that the getaddrinfo() implementation in the\nGNU C Library did not properly track memory allocations. An attacker\ncould use this to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS. (CVE-2016-5417)\n\nAndreas Schwab discovered that the GNU C Library on ARM 32-bit\nplatforms did not properly set up execution contexts. An attacker\ncould use this to cause a denial of service. (CVE-2016-6323)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.16","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.16"}],"trusty":[{"name":"eglibc","version":"2.19-0ubuntu6.10","description":"GNU C Library","is_source":true},{"name":"eglibc-source","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"glibc-doc","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-dev-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-pic","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-prof","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-dns-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-files-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"multiarch-support","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"nscd","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"}],"xenial":[{"name":"glibc","version":"2.23-0ubuntu6","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"glibc-source","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-dev-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6","version":"2.23-0ubuntu6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-pic","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-udeb","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales-all","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"multiarch-support","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"nscd","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5180","CVE-2015-8982","CVE-2015-8983","CVE-2015-8984","CVE-2016-1234","CVE-2016-3706","CVE-2016-4429","CVE-2016-5417","CVE-2016-6323"]}]},{"id":"CVE-2015-8983","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:16.148927+00:00","description":"\nInteger overflow in the _IO_wstr_overflow function in libio/wstrops.c in\nthe GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent\nattackers to cause a denial of service (application crash) or possibly\nexecute arbitrary code via vectors related to computing a size in bytes,\nwhich triggers a heap-based buffer overflow.","ubuntu_description":"\nIt was discovered that an integer overflow existed in the\n_IO_wstr_overflow() function of the GNU C Library. An attacker\ncould use this to cause a denial of service or possibly execute\narbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=17269","http://www.openwall.com/lists/oss-security/2015/02/22/15","https://ubuntu.com/security/notices/USN-3239-1","https://www.cve.org/CVERecord?id=CVE-2015-8983"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779587"],"patches":{"eglibc":[],"glibc":["upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=bdf1ff052a8e23d637f2c838fa5642d78fcedc33"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.19-0ubuntu6.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3239-1"],"notices":[{"id":"USN-3239-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2017-03-21T02:58:45.626524","description":"It was discovered that the GNU C Library incorrectly handled the\nstrxfrm() function. An attacker could use this issue to cause a denial\nof service or possibly execute arbitrary code. This issue only affected\nUbuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)\n\nIt was discovered that an integer overflow existed in the\n_IO_wstr_overflow() function of the GNU C Library. An attacker could\nuse this to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04\nLTS. (CVE-2015-8983)\n\nIt was discovered that the fnmatch() function in the GNU C Library\ndid not properly handle certain malformed patterns. An attacker could\nuse this to cause a denial of service. This issue only affected Ubuntu\n12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8984)\n\nAlexander Cherepanov discovered a stack-based buffer overflow in the\nglob implementation of the GNU C Library. An attacker could use this\nto specially craft a directory layout and cause a denial of service.\n(CVE-2016-1234)\n\nFlorian Weimer discovered a NULL pointer dereference in the DNS\nresolver of the GNU C Library. An attacker could use this to cause\na denial of service. (CVE-2015-5180)\n\nMichael Petlan discovered an unbounded stack allocation in the\ngetaddrinfo() function of the GNU C Library. An attacker could use\nthis to cause a denial of service. (CVE-2016-3706)\n\nAldy Hernandez discovered an unbounded stack allocation in the sunrpc\nimplementation in the GNU C Library. An attacker could use this to\ncause a denial of service. (CVE-2016-4429)\n\nTim Ruehsen discovered that the getaddrinfo() implementation in the\nGNU C Library did not properly track memory allocations. An attacker\ncould use this to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS. (CVE-2016-5417)\n\nAndreas Schwab discovered that the GNU C Library on ARM 32-bit\nplatforms did not properly set up execution contexts. An attacker\ncould use this to cause a denial of service. (CVE-2016-6323)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.16","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.16"}],"trusty":[{"name":"eglibc","version":"2.19-0ubuntu6.10","description":"GNU C Library","is_source":true},{"name":"eglibc-source","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"glibc-doc","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-dev-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-pic","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-prof","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-dns-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-files-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"multiarch-support","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"nscd","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"}],"xenial":[{"name":"glibc","version":"2.23-0ubuntu6","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"glibc-source","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-dev-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6","version":"2.23-0ubuntu6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-pic","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-udeb","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales-all","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"multiarch-support","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"nscd","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5180","CVE-2015-8982","CVE-2015-8983","CVE-2015-8984","CVE-2016-1234","CVE-2016-3706","CVE-2016-4429","CVE-2016-5417","CVE-2016-6323"]}]},{"id":"CVE-2015-8982","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:16.148927+00:00","description":"\nInteger overflow in the strxfrm function in the GNU C Library (aka glibc or\nlibc6) before 2.21 allows context-dependent attackers to cause a denial of\nservice (crash) or possibly execute arbitrary code via a long string, which\ntriggers a stack-based buffer overflow.","ubuntu_description":"\nIt was discovered that the GNU C Library incorrectly handled the\nstrxfrm() function. An attacker could use this issue to cause a\ndenial of service or possibly execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=16009","https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commit;h=0f9e585480ed","http://openwall.com/lists/oss-security/2015/09/08/2","https://ubuntu.com/security/notices/USN-3239-1","https://www.cve.org/CVERecord?id=CVE-2015-8982"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=803927"],"patches":{"eglibc":[],"glibc":[]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.19-0ubuntu6.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.21","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.23-0ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3239-1"],"notices":[{"id":"USN-3239-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2017-03-21T02:58:45.626524","description":"It was discovered that the GNU C Library incorrectly handled the\nstrxfrm() function. An attacker could use this issue to cause a denial\nof service or possibly execute arbitrary code. This issue only affected\nUbuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8982)\n\nIt was discovered that an integer overflow existed in the\n_IO_wstr_overflow() function of the GNU C Library. An attacker could\nuse this to cause a denial of service or possibly execute arbitrary\ncode. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04\nLTS. (CVE-2015-8983)\n\nIt was discovered that the fnmatch() function in the GNU C Library\ndid not properly handle certain malformed patterns. An attacker could\nuse this to cause a denial of service. This issue only affected Ubuntu\n12.04 LTS and Ubuntu 14.04 LTS. (CVE-2015-8984)\n\nAlexander Cherepanov discovered a stack-based buffer overflow in the\nglob implementation of the GNU C Library. An attacker could use this\nto specially craft a directory layout and cause a denial of service.\n(CVE-2016-1234)\n\nFlorian Weimer discovered a NULL pointer dereference in the DNS\nresolver of the GNU C Library. An attacker could use this to cause\na denial of service. (CVE-2015-5180)\n\nMichael Petlan discovered an unbounded stack allocation in the\ngetaddrinfo() function of the GNU C Library. An attacker could use\nthis to cause a denial of service. (CVE-2016-3706)\n\nAldy Hernandez discovered an unbounded stack allocation in the sunrpc\nimplementation in the GNU C Library. An attacker could use this to\ncause a denial of service. (CVE-2016-4429)\n\nTim Ruehsen discovered that the getaddrinfo() implementation in the\nGNU C Library did not properly track memory allocations. An attacker\ncould use this to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS. (CVE-2016-5417)\n\nAndreas Schwab discovered that the GNU C Library on ARM 32-bit\nplatforms did not properly set up execution contexts. An attacker\ncould use this to cause a denial of service. (CVE-2016-6323)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.16","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.16"}],"trusty":[{"name":"eglibc","version":"2.19-0ubuntu6.10","description":"GNU C Library","is_source":true},{"name":"eglibc-source","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"glibc-doc","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc-dev-bin","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-armel","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-dev-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-i386","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-pic","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-ppc64","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-prof","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libc6-x32","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-dns-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"libnss-files-udeb","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"multiarch-support","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"},{"name":"nscd","version":"2.19-0ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.10","pocket":"security"}],"xenial":[{"name":"glibc","version":"2.23-0ubuntu6","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"glibc-source","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc-dev-bin","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6","version":"2.23-0ubuntu6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-armel","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-dev-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-i386","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-pic","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-ppc64","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-s390","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-udeb","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"libc6-x32","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"locales-all","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"multiarch-support","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"},{"name":"nscd","version":"2.23-0ubuntu6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5180","CVE-2015-8982","CVE-2015-8983","CVE-2015-8984","CVE-2016-1234","CVE-2016-3706","CVE-2016-4429","CVE-2016-5417","CVE-2016-6323"]}]},{"id":"CVE-2015-8948","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:06.305192+00:00","description":"\nidn in GNU libidn before 1.33 might allow remote attackers to obtain\nsensitive memory information by reading a zero byte as input, which\ntriggers an out-of-bounds read.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=146910769415616&w=2","https://ubuntu.com/security/notices/USN-3068-1","https://www.cve.org/CVERecord?id=CVE-2015-8948"],"bugs":[""],"patches":{"libidn":["upstream: http://git.savannah.gnu.org/cgit/libidn.git/commit/?id=570e68886c41c2e765e6218cb317d9a9a447a041"]},"tags":{},"packages":[{"name":"libidn","source":"https://ubuntu.com/security/cve?package=libidn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libidn","debian":"https://tracker.debian.org/pkg/libidn","statuses":[{"release_codename":"precise","status":"released","description":"1.23-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.28-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.33-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.32-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.33-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.33-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3068-1"],"notices":[{"id":"USN-3068-1","title":"Libidn vulnerabilities","summary":"Several security issues were fixed in Libidn.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-08-24T13:30:51.011300","description":"Thijs Alkemade, Gustavo Grieco, Daniel Stenberg, and Nikos\nMavrogiannopoulos discovered that Libidn incorrectly handled invalid UTF-8\ncharacters. A remote attacker could use this issue to cause Libidn to\ncrash, resulting in a denial of service, or possibly disclose sensitive\nmemory. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\n(CVE-2015-2059)\n\nHanno Böck discovered that Libidn incorrectly handled certain input. A\nremote attacker could possibly use this issue to cause Libidn to crash,\nresulting in a denial of service. (CVE-2015-8948, CVE-2016-6262,\nCVE-2016-6261, CVE-2016-6263)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libidn","version":"1.23-2ubuntu0.1","description":"implementation of IETF IDN specifications","is_source":true},{"name":"libidn11","version":"1.23-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.23-2ubuntu0.1"}],"trusty":[{"name":"libidn","version":"1.28-1ubuntu2.1","description":"implementation of IETF IDN specifications","is_source":true},{"name":"idn","version":"1.28-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.28-1ubuntu2.1","pocket":"security"},{"name":"libidn11","version":"1.28-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.28-1ubuntu2.1","pocket":"security"},{"name":"libidn11-dev","version":"1.28-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.28-1ubuntu2.1","pocket":"security"},{"name":"libidn11-java","version":"1.28-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.28-1ubuntu2.1","pocket":"security"}],"xenial":[{"name":"libidn","version":"1.32-3ubuntu1.1","description":"implementation of IETF IDN specifications","is_source":true},{"name":"idn","version":"1.32-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.32-3ubuntu1.1","pocket":"security"},{"name":"libidn11","version":"1.32-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.32-3ubuntu1.1","pocket":"security"},{"name":"libidn11-dev","version":"1.32-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.32-3ubuntu1.1","pocket":"security"},{"name":"libidn11-java","version":"1.32-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libidn","version_link":"https://launchpad.net/ubuntu/+source/libidn/1.32-3ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-2059","CVE-2015-8948","CVE-2016-6261","CVE-2016-6262","CVE-2016-6263"]}]},{"id":"CVE-2015-8934","published":"2015-12-31T00:00:00","updated_at":"2025-08-25T21:50:00.013332+00:00","description":"\nThe copy_from_lzss_window function in archive_read_support_format_rar.c in\nlibarchive 3.2.0 and earlier allows remote attackers to cause a denial of\nservice (out-of-bounds heap read) via a crafted rar file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3033-1","https://www.cve.org/CVERecord?id=CVE-2015-8934"],"bugs":["https://github.com/libarchive/libarchive/issues/521"],"patches":{"libarchive":["upstream: https://github.com/libarchive/libarchive/commit/603454e"]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"released","description":"3.0.3-6ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.2-7ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"3.1.2-11ubuntu0.15.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.1.2-11ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3033-1"],"notices":[{"id":"USN-3033-1","title":"libarchive vulnerabilities","summary":"libarchive could be made to crash or run programs if it opened a specially\ncrafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-07-14T17:55:04.967093","description":"Hanno Böck discovered that libarchive contained multiple security issues\nwhen processing certain malformed archive files. A remote attacker could\nuse this issue to cause libarchive to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2015-8916, CVE-2015-8917\nCVE-2015-8919, CVE-2015-8920, CVE-2015-8921, CVE-2015-8922, CVE-2015-8923,\nCVE-2015-8924, CVE-2015-8925, CVE-2015-8926, CVE-2015-8928, CVE-2015-8930,\nCVE-2015-8931, CVE-2015-8932, CVE-2015-8933, CVE-2015-8934, CVE-2016-5844)\n\nMarcin \"Icewall\" Noga discovered that libarchive contained multiple\nsecurity issues when processing certain malformed archive files. A remote\nattacker could use this issue to cause libarchive to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2016-4300,\nCVE-2016-4302)\n\nIt was discovered that libarchive incorrectly handled memory allocation\nwith large cpio symlinks. A remote attacker could use this issue to\npossibly cause libarchive to crash, resulting in a denial of service.\n(CVE-2016-4809)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libarchive","version":"3.0.3-6ubuntu1.3","description":"Library to read/write archive files","is_source":true},{"name":"libarchive12","version":"3.0.3-6ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.3"}],"trusty":[{"name":"libarchive","version":"3.1.2-7ubuntu2.3","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"bsdtar","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"},{"name":"libarchive13","version":"3.1.2-7ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.3","pocket":"security"}],"wily":[{"name":"libarchive","version":"3.1.2-11ubuntu0.15.10.2","description":"Library to read/write archive files","is_source":true},{"name":"libarchive13","version":"3.1.2-11ubuntu0.15.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.15.10.2"}],"xenial":[{"name":"libarchive","version":"3.1.2-11ubuntu0.16.04.2","description":"Library to read/write archive files","is_source":true},{"name":"bsdcpio","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"bsdtar","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive-dev","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"},{"name":"libarchive13","version":"3.1.2-11ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libarchive","version_link":"https://launchpad.net/ubuntu/+source/libarchive/3.1.2-11ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8916","CVE-2015-8917","CVE-2015-8919","CVE-2015-8920","CVE-2015-8921","CVE-2015-8922","CVE-2015-8923","CVE-2015-8924","CVE-2015-8925","CVE-2015-8926","CVE-2015-8928","CVE-2015-8930","CVE-2015-8931","CVE-2015-8932","CVE-2015-8933","CVE-2015-8934","CVE-2016-4300","CVE-2016-4302","CVE-2016-4809","CVE-2016-5844"]}]}],"offset":61860,"limit":20,"total_results":79316}