{"cves":[{"id":"CVE-2015-5732","published":"2015-11-09T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the form function in the\nWP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress\nbefore 4.2.4 allows remote attackers to inject arbitrary web script or HTML\nvia a widget title.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-5732"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=794560"],"patches":{"wordpress":["upstream: https://core.trac.wordpress.org/changeset/33529"]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5731","published":"2015-11-09T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in wp-admin/post.php in\nWordPress before 4.2.4 allows remote attackers to hijack the authentication\nof administrators for requests that lock a post, and consequently cause a\ndenial of service (editing blockage), via a get-post-lock action.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-5731"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=794560"],"patches":{"wordpress":["upstream: https://core.trac.wordpress.org/changeset/33542","upstream: https://core.trac.wordpress.org/changeset/33543"]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5730","published":"2015-11-09T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe sanitize_widget_instance function in\nwp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does\nnot use a constant-time comparison for widgets, which allows remote\nattackers to conduct a timing side-channel attack by measuring the delay\nbefore inequality is calculated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://core.trac.wordpress.org/changeset/33535","https://core.trac.wordpress.org/changeset/33536","https://www.cve.org/CVERecord?id=CVE-2015-5730"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=794560"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2213","published":"2015-11-09T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in the wp_untrash_post_comments function in\nwp-includes/post.php in WordPress before 4.2.4 allows remote attackers to\nexecute arbitrary SQL commands via a comment that is mishandled after\nretrieval from the trash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-2213"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=794560"],"patches":{"wordpress":["upstream: https://core.trac.wordpress.org/changeset/33555","upstream: https://core.trac.wordpress.org/changeset/33556"]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.2.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7940","published":"2015-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Bouncy Castle Java library before 1.51 does not validate a point is\nwithing the elliptic curve, which makes it easier for remote attackers to\nobtain private keys via a series of crafted elliptic curve Diffie Hellman\n(ECDH) key exchanges, aka an \"invalid curve attack.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no reverse depends in main"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://web-in-security.blogspot.ca/2015/09/practical-invalid-curve-attacks.html","https://ubuntu.com/security/notices/USN-3727-1","https://www.cve.org/CVERecord?id=CVE-2015-7940"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802671"],"patches":{"bouncycastle":["upstream: https://github.com/bcgit/bc-java/commit/5cb2f0578e6ec8f0d67e59d05d8c4704d8e05f83","upstream: https://github.com/bcgit/bc-java/commit/e25e94a046a6934819133886439984e2fecb2b04"]},"tags":{},"packages":[{"name":"bouncycastle","source":"https://ubuntu.com/security/cve?package=bouncycastle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bouncycastle","debian":"https://tracker.debian.org/pkg/bouncycastle","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.57-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.59-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.49+dfsg-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.51-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.51-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3727-1"],"notices":[{"id":"USN-3727-1","title":"Bouncy Castle vulnerabilities","summary":"Several security issues were fixed in Bouncy Castle.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-08-01T14:56:58.021268","description":"It was discovered that Bouncy Castle incorrectly handled certain crypto\nalgorithms. A remote attacker could possibly use these issues to obtain\nsensitive information, including private keys.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"bouncycastle","version":"1.49+dfsg-2ubuntu0.1","description":"Java implementation of cryptographic algorithms","is_source":true},{"name":"libbcmail-java","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libbcmail-java-doc","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libbcpg-java","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libbcpg-java-doc","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libbcpkix-java","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libbcpkix-java-doc","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libbcprov-java","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libbcprov-java-doc","version":"1.49+dfsg-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bouncycastle","version_link":"https://launchpad.net/ubuntu/+source/bouncycastle/1.49+dfsg-2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-6644","CVE-2015-7940","CVE-2016-1000338","CVE-2016-1000339","CVE-2016-1000341","CVE-2016-1000342","CVE-2016-1000343","CVE-2016-1000345","CVE-2016-1000346"]}]},{"id":"CVE-2015-7295","published":"2015-11-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nhw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in\nQEMU, when big or mergeable receive buffers are not supported, allows\nremote attackers to cause a denial of service (guest network consumption)\nvia a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/09/18/5","https://ubuntu.com/security/notices/USN-2828-1","https://www.cve.org/CVERecord?id=CVE-2015-7295"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=799452"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=ce317461573bac12b10d67699b4ddf1f97cf066c","upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=29b9f5efd78ae0f9cc02dd169b6e80d2c404bade","upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=0cf33fb6b49a19de32859e2cdc6021334f448fb3","other: https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg04729.html","other: https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg04730.html","other: https://lists.gnu.org/archive/html/qemu-devel/2015-09/msg04731.html"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.21","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:2.4+dfsg-4","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:2.2+dfsg-5expubuntu9.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:2.3+dfsg-5ubuntu9.1","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.26","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2828-1"],"notices":[{"id":"USN-2828-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2015-12-03T12:34:36.132599","description":"Jason Wang discovered that QEMU incorrectly handled the virtio-net device.\nA remote attacker could use this issue to cause guest network consumption,\nresulting in a denial of service. (CVE-2015-7295)\n\nQinghao Tang and Ling Liu discovered that QEMU incorrectly handled the\npcnet driver when used in loopback mode. A malicious guest could use this\nissue to cause a denial of service, or possibly execute arbitrary code on\nthe host as the user running the QEMU process. In the default installation,\nwhen QEMU is used with libvirt, attackers would be isolated by the libvirt\nAppArmor profile. (CVE-2015-7504)\n\nLing Liu and Jason Wang discovered that QEMU incorrectly handled the\npcnet driver. A remote attacker could use this issue to cause a denial of\nservice, or possibly execute arbitrary code on the host as the user running\nthe QEMU process. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2015-7512)\n\nQinghao Tang discovered that QEMU incorrectly handled the eepro100 driver.\nA malicious guest could use this issue to cause an infinite loop, leading\nto a denial of service. (CVE-2015-8345)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.26","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.26"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.21","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.21","pocket":"security"}],"vivid":[{"name":"qemu","version":"1:2.2+dfsg-5expubuntu9.7","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"},{"name":"qemu-system-aarch64","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"},{"name":"qemu-system-arm","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"},{"name":"qemu-system-mips","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"},{"name":"qemu-system-misc","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"},{"name":"qemu-system-ppc","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"},{"name":"qemu-system-sparc","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"},{"name":"qemu-system-x86","version":"1:2.2+dfsg-5expubuntu9.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.7"}],"wily":[{"name":"qemu","version":"1:2.3+dfsg-5ubuntu9.1","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"},{"name":"qemu-system-aarch64","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"},{"name":"qemu-system-arm","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"},{"name":"qemu-system-mips","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"},{"name":"qemu-system-misc","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"},{"name":"qemu-system-ppc","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"},{"name":"qemu-system-sparc","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"},{"name":"qemu-system-x86","version":"1:2.3+dfsg-5ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.3+dfsg-5ubuntu9.1"}]},"type":"USN","cves_ids":["CVE-2015-7295","CVE-2015-7504","CVE-2015-7512","CVE-2015-8345"]}]},{"id":"CVE-2015-2697","published":"2015-11-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos\n5 (aka krb5) before 1.14 allows remote authenticated users to cause a\ndenial of service (out-of-bounds read and KDC crash) via an initial '\\0'\ncharacter in a long realm field within a TGS request.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"kdc crash"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2810-1","https://www.cve.org/CVERecord?id=CVE-2015-2697"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=803088","http://krbdev.mit.edu/rt/Ticket/Display.html?id=8252"],"patches":{"krb5":["upstream: https://github.com/krb5/krb5/commit/f0c094a1b745d91ef2f9a4eae2149aac026a5789"]},"tags":{"krb5":["universe-binary"]},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"precise","status":"released","description":"1.10+dfsg~beta1-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.2+dfsg-3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+dfsg-18ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.2+dfsg-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2810-1"],"notices":[{"id":"USN-2810-1","title":"Kerberos vulnerabilities","summary":"Several security issues were fixed in Kerberos.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-11-12T17:50:55.940907","description":"It was discovered that the Kerberos kpasswd service incorrectly handled\ncertain UDP packets. A remote attacker could possibly use this issue to\ncause resource consumption, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2002-2443)\n\nIt was discovered that Kerberos incorrectly handled null bytes in certain\ndata fields. A remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-5355)\n\nIt was discovered that the Kerberos kdcpreauth modules incorrectly tracked\ncertain client requests. A remote attacker could possibly use this issue\nto bypass intended preauthentication requirements. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-2694)\n\nIt was discovered that Kerberos incorrectly handled certain SPNEGO packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2695)\n\nIt was discovered that Kerberos incorrectly handled certain IAKERB packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2696, CVE-2015-2698)\n\nIt was discovered that Kerberos incorrectly handled certain TGS requests. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2015-2697)\n","is_hidden":false,"release_packages":{"precise":[{"name":"krb5","version":"1.10+dfsg~beta1-2ubuntu0.7","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc-ldap","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-pkinit","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-user","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssapi-krb5-2","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssrpc4","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libk5crypto3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkadm5clnt-mit8","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkdb5-6","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5-3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb53","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5support0","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"}],"trusty":[{"name":"krb5","version":"1.12+dfsg-2ubuntu5.2","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-doc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-gss-samples","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-locales","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-multidev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-otp","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-pkinit","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-user","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssrpc4","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libk5crypto3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5clnt-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit8","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkdb5-7","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5support0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"}],"vivid":[{"name":"krb5","version":"1.12.1+dfsg-18ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-otp","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-pkinit","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-user","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssrpc4","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libk5crypto3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkdb5-7","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrad0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5-3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5support0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"}],"wily":[{"name":"krb5","version":"1.13.2+dfsg-2ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-k5tls","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-otp","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-pkinit","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-user","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssrpc4","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libk5crypto3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkdb5-8","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrad0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5-3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5support0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2002-2443","CVE-2014-5355","CVE-2015-2694","CVE-2015-2695","CVE-2015-2696","CVE-2015-2697","CVE-2015-2698"]}]},{"id":"CVE-2015-2696","published":"2015-11-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on\nan inappropriate context handle, which allows remote attackers to cause a\ndenial of service (incorrect pointer read and process crash) via a crafted\nIAKERB packet that is mishandled during a gss_inquire_context call.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Upstream fix caused a new security issue (CVE-2015-2698)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2810-1","https://www.cve.org/CVERecord?id=CVE-2015-2696"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=803084","http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244"],"patches":{"krb5":["upstream: https://github.com/krb5/krb5/commit/e04f0283516e80d2f93366e0d479d13c9b5c8c2a","upstream: https://github.com/krb5/krb5/commit/a705b1160ce7f0c5f23b9859c4c6c707503fbfdc","upstream: https://github.com/krb5/krb5/commit/92d6dd045dfc06cc03d20b327a6ee7a71e6bc24d"]},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"precise","status":"released","description":"1.10+dfsg~beta1-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.2+dfsg-3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+dfsg-18ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.2+dfsg-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2810-1"],"notices":[{"id":"USN-2810-1","title":"Kerberos vulnerabilities","summary":"Several security issues were fixed in Kerberos.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-11-12T17:50:55.940907","description":"It was discovered that the Kerberos kpasswd service incorrectly handled\ncertain UDP packets. A remote attacker could possibly use this issue to\ncause resource consumption, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2002-2443)\n\nIt was discovered that Kerberos incorrectly handled null bytes in certain\ndata fields. A remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-5355)\n\nIt was discovered that the Kerberos kdcpreauth modules incorrectly tracked\ncertain client requests. A remote attacker could possibly use this issue\nto bypass intended preauthentication requirements. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-2694)\n\nIt was discovered that Kerberos incorrectly handled certain SPNEGO packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2695)\n\nIt was discovered that Kerberos incorrectly handled certain IAKERB packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2696, CVE-2015-2698)\n\nIt was discovered that Kerberos incorrectly handled certain TGS requests. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2015-2697)\n","is_hidden":false,"release_packages":{"precise":[{"name":"krb5","version":"1.10+dfsg~beta1-2ubuntu0.7","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc-ldap","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-pkinit","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-user","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssapi-krb5-2","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssrpc4","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libk5crypto3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkadm5clnt-mit8","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkdb5-6","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5-3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb53","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5support0","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"}],"trusty":[{"name":"krb5","version":"1.12+dfsg-2ubuntu5.2","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-doc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-gss-samples","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-locales","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-multidev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-otp","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-pkinit","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-user","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssrpc4","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libk5crypto3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5clnt-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit8","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkdb5-7","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5support0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"}],"vivid":[{"name":"krb5","version":"1.12.1+dfsg-18ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-otp","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-pkinit","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-user","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssrpc4","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libk5crypto3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkdb5-7","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrad0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5-3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5support0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"}],"wily":[{"name":"krb5","version":"1.13.2+dfsg-2ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-k5tls","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-otp","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-pkinit","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-user","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssrpc4","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libk5crypto3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkdb5-8","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrad0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5-3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5support0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2002-2443","CVE-2014-5355","CVE-2015-2694","CVE-2015-2695","CVE-2015-2696","CVE-2015-2697","CVE-2015-2698"]}]},{"id":"CVE-2015-2695","published":"2015-11-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14\nrelies on an inappropriate context handle, which allows remote attackers to\ncause a denial of service (incorrect pointer read and process crash) via a\ncrafted SPNEGO packet that is mishandled during a gss_inquire_context call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2810-1","https://www.cve.org/CVERecord?id=CVE-2015-2695"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=803083","http://krbdev.mit.edu/rt/Ticket/Display.html?id=8244"],"patches":{"krb5":["upstream: https://github.com/krb5/krb5/commit/b51b33f2bc5d1497ddf5bd107f791c101695000d","upstream: https://github.com/krb5/krb5/commit/222b09f6e2f536354555f2a0dedfe29fc10c01d6"]},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"precise","status":"released","description":"1.10+dfsg~beta1-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.2+dfsg-3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+dfsg-18ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.2+dfsg-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2810-1"],"notices":[{"id":"USN-2810-1","title":"Kerberos vulnerabilities","summary":"Several security issues were fixed in Kerberos.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-11-12T17:50:55.940907","description":"It was discovered that the Kerberos kpasswd service incorrectly handled\ncertain UDP packets. A remote attacker could possibly use this issue to\ncause resource consumption, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2002-2443)\n\nIt was discovered that Kerberos incorrectly handled null bytes in certain\ndata fields. A remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-5355)\n\nIt was discovered that the Kerberos kdcpreauth modules incorrectly tracked\ncertain client requests. A remote attacker could possibly use this issue\nto bypass intended preauthentication requirements. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-2694)\n\nIt was discovered that Kerberos incorrectly handled certain SPNEGO packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2695)\n\nIt was discovered that Kerberos incorrectly handled certain IAKERB packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2696, CVE-2015-2698)\n\nIt was discovered that Kerberos incorrectly handled certain TGS requests. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2015-2697)\n","is_hidden":false,"release_packages":{"precise":[{"name":"krb5","version":"1.10+dfsg~beta1-2ubuntu0.7","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc-ldap","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-pkinit","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-user","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssapi-krb5-2","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssrpc4","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libk5crypto3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkadm5clnt-mit8","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkdb5-6","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5-3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb53","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5support0","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"}],"trusty":[{"name":"krb5","version":"1.12+dfsg-2ubuntu5.2","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-doc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-gss-samples","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-locales","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-multidev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-otp","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-pkinit","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-user","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssrpc4","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libk5crypto3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5clnt-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit8","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkdb5-7","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5support0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"}],"vivid":[{"name":"krb5","version":"1.12.1+dfsg-18ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-otp","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-pkinit","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-user","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssrpc4","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libk5crypto3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkdb5-7","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrad0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5-3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5support0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"}],"wily":[{"name":"krb5","version":"1.13.2+dfsg-2ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-k5tls","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-otp","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-pkinit","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-user","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssrpc4","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libk5crypto3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkdb5-8","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrad0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5-3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5support0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2002-2443","CVE-2014-5355","CVE-2015-2694","CVE-2015-2695","CVE-2015-2696","CVE-2015-2697","CVE-2015-2698"]}]},{"id":"CVE-2015-7809","published":"2015-11-06T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe displayBlock function Template.php in Sensio Labs Twig before 1.20.0,\nwhen Sandbox mode is enabled, allows remote attackers to execute arbitrary\ncode via the _self variable in a template.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://symfony.com/blog/security-release-twig-1-20-0","https://www.cve.org/CVERecord?id=CVE-2015-7809"],"bugs":[""],"patches":{"twig":[]},"tags":{},"packages":[{"name":"twig","source":"https://ubuntu.com/security/cve?package=twig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=twig","debian":"https://tracker.debian.org/pkg/twig","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.20.0-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.16.2-1+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.20.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7763","published":"2015-11-06T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nrx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x\nbefore 1.7.33 does not properly initialize padding at the end of an Rx\nacknowledgement (ACK) packet, which allows remote attackers to obtain\nsensitive information by (1) conducting a replay attack or (2) sniffing the\nnetwork.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.openafs.org/security","https://www.openafs.org/pages/security/OPENAFS-SA-2015-007.txt","https://www.cve.org/CVERecord?id=CVE-2015-7763"],"bugs":[""],"patches":{"openafs":["upstream: https://www.openafs.org/pages/security/OPENAFS-SA-2015-007.master.patch","upstream: https://www.openafs.org/pages/security/OPENAFS-SA-2015-007.1.6.patch"]},"tags":{},"packages":[{"name":"openafs","source":"https://ubuntu.com/security/cve?package=openafs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openafs","debian":"https://tracker.debian.org/pkg/openafs","statuses":[{"release_codename":"precise","status":"released","description":"1.6.1-1+ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.7-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.15-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.6.15-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7762","published":"2015-11-06T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nrx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly\ninitialize the padding of a data structure when constructing an Rx\nacknowledgement (ACK) packet, which allows remote attackers to obtain\nsensitive information by (1) conducting a replay attack or (2) sniffing the\nnetwork.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.openafs.org/security","https://www.openafs.org/pages/security/OPENAFS-SA-2015-007.txt","https://www.cve.org/CVERecord?id=CVE-2015-7762"],"bugs":[""],"patches":{"openafs":["upstream: https://www.openafs.org/pages/security/OPENAFS-SA-2015-007.master.patch","upstream: https://www.openafs.org/pages/security/OPENAFS-SA-2015-007.1.6.patch"]},"tags":{},"packages":[{"name":"openafs","source":"https://ubuntu.com/security/cve?package=openafs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openafs","debian":"https://tracker.debian.org/pkg/openafs","statuses":[{"release_codename":"precise","status":"released","description":"1.6.1-1+ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.7-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.15-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.6.15-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9749","published":"2015-11-06T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSquid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest\nauthentication is used, allow remote authenticated users to retain access\nby leveraging a stale nonce, aka \"Nonce replay vulnerability.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bugs.squid-cache.org/show_bug.cgi?id=4066","http://bazaar.launchpad.net/~squid/squid/3.4/revision/13211 (Squid 3.4)","http://bazaar.launchpad.net/~squid/squid/3.5/revision/13735 (Squid 3.5)","https://www.cve.org/CVERecord?id=CVE-2014-9749"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776464"],"patches":{"squid3":[]},"tags":{},"packages":[{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8075","published":"2015-11-06T11:59:00","updated_at":"2025-08-04T19:24:32.789323+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none.\nReason: This candidate was withdrawn by its CNA. Further investigation\nshowed that it was not a security issue. Notes: none","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://permalink.gmane.org/gmane.comp.audio.libsndfile.devel/681","http://www.openwall.com/lists/oss-security/2015/11/03/5","https://www.cve.org/CVERecord?id=CVE-2015-8075"],"bugs":[""],"patches":{"libsndfile":["upstream: https://github.com/erikd/libsndfile/commit/495c2877e1c841fbb420383551547d2ca60533c6"]},"tags":{},"packages":[{"name":"libsndfile","source":"https://ubuntu.com/security/cve?package=libsndfile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsndfile","debian":"https://tracker.debian.org/pkg/libsndfile","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2698","published":"2015-11-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in\nMIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a\ncertain pointer, which allows remote authenticated users to cause a denial\nof service (memory corruption) or possibly have unspecified other impact by\ninteracting with an application that calls the gss_export_sec_context\nfunction. NOTE: this vulnerability exists because of an incorrect fix for\nCVE-2015-2696.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"We're not technically affected since CVE-2015-2696 hasn't been\nfixed yet. Marking as needed so that we don't miss this fix while fixing\nCVE-2015-2696."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2810-1","https://www.cve.org/CVERecord?id=CVE-2015-2698"],"bugs":[""],"patches":{"krb5":["upstream: https://github.com/krb5/krb5/commit/3db8dfec1ef50ddd78d6ba9503185995876a39fd"]},"tags":{},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"precise","status":"released","description":"1.10+dfsg~beta1-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.2+dfsg-4","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+dfsg-18ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.13.2+dfsg-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2810-1"],"notices":[{"id":"USN-2810-1","title":"Kerberos vulnerabilities","summary":"Several security issues were fixed in Kerberos.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-11-12T17:50:55.940907","description":"It was discovered that the Kerberos kpasswd service incorrectly handled\ncertain UDP packets. A remote attacker could possibly use this issue to\ncause resource consumption, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2002-2443)\n\nIt was discovered that Kerberos incorrectly handled null bytes in certain\ndata fields. A remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-5355)\n\nIt was discovered that the Kerberos kdcpreauth modules incorrectly tracked\ncertain client requests. A remote attacker could possibly use this issue\nto bypass intended preauthentication requirements. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-2694)\n\nIt was discovered that Kerberos incorrectly handled certain SPNEGO packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2695)\n\nIt was discovered that Kerberos incorrectly handled certain IAKERB packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2696, CVE-2015-2698)\n\nIt was discovered that Kerberos incorrectly handled certain TGS requests. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2015-2697)\n","is_hidden":false,"release_packages":{"precise":[{"name":"krb5","version":"1.10+dfsg~beta1-2ubuntu0.7","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc-ldap","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-pkinit","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-user","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssapi-krb5-2","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssrpc4","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libk5crypto3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkadm5clnt-mit8","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkdb5-6","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5-3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb53","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5support0","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"}],"trusty":[{"name":"krb5","version":"1.12+dfsg-2ubuntu5.2","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-doc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-gss-samples","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-locales","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-multidev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-otp","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-pkinit","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-user","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssrpc4","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libk5crypto3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5clnt-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit8","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkdb5-7","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5support0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"}],"vivid":[{"name":"krb5","version":"1.12.1+dfsg-18ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-otp","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-pkinit","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-user","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssrpc4","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libk5crypto3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkdb5-7","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrad0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5-3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5support0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"}],"wily":[{"name":"krb5","version":"1.13.2+dfsg-2ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-k5tls","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-otp","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-pkinit","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-user","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssrpc4","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libk5crypto3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkdb5-8","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrad0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5-3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5support0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2002-2443","CVE-2014-5355","CVE-2015-2694","CVE-2015-2695","CVE-2015-2696","CVE-2015-2697","CVE-2015-2698"]}]},{"id":"CVE-2015-7192","published":"2015-11-05T05:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe accessibility-tools feature in Mozilla Firefox before 42.0 on OS X\nimproperly interacts with the implementation of the TABLE element, which\nallows remote attackers to cause a denial of service (application crash) or\npossibly execute arbitrary code by using an NSAccessibilityIndexAttribute\nvalue to reference a row index.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"OS X only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-126/","https://www.cve.org/CVERecord?id=CVE-2015-7192"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"42.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7191","published":"2015-11-05T05:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 42.0 on Android improperly restricts URL strings in\nintents, which allows attackers to conduct cross-site scripting (XSS)\nattacks via vectors involving an intent: URL and fallback navigation, aka\n\"Universal XSS (UXSS).\"","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Android only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-125/","https://www.cve.org/CVERecord?id=CVE-2015-7191"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"42.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7190","published":"2015-11-05T05:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Search feature in Mozilla Firefox before 42.0 on Android through 4.4\nsupports search-engine URL registration through an intent and can access\nthis URL in a privileged context in conjunction with the crash reporter,\nwhich allows attackers to read log files and visit file: URLs of HTML\ndocuments via a crafted application.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Android only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-124/","https://www.cve.org/CVERecord?id=CVE-2015-7190"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"42.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7186","published":"2015-11-05T05:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 42.0 on Android allows user-assisted remote\nattackers to bypass the Same Origin Policy and trigger (1) a download or\n(2) cached profile-data reading via a file: URL in a saved HTML document.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Android only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-120/","https://www.cve.org/CVERecord?id=CVE-2015-7186"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"42.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7185","published":"2015-11-05T05:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 42.0 on Android does not ensure that the address bar\nis restored upon fullscreen-mode exit, which allows remote attackers to\nspoof the address bar via crafted JavaScript code.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Android only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-119/","https://www.cve.org/CVERecord?id=CVE-2015-7185"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"42.0","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":62300,"limit":20,"total_results":79316}