{"cves":[{"id":"CVE-2015-5212","published":"2015-11-03T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger underflow in LibreOffice before 4.4.5 and Apache OpenOffice before\n4.1.2, when the configuration setting \"Load printer settings with the\ndocument\" is enabled, allows remote attackers to cause a denial of service\n(memory corruption and application crash) or possibly execute arbitrary\ncode via crafted PrinterSetup data in an ODF document.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/","https://ubuntu.com/security/notices/USN-2793-1","https://www.cve.org/CVERecord?id=CVE-2015-5212"],"bugs":[""],"patches":{"libreoffice":[]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"precise","status":"released","description":"1:3.5.7-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.8-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:4.4.6~rc3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:5.0.2-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2793-1"],"notices":[{"id":"USN-2793-1","title":"LibreOffice vulnerabilities","summary":"Several security issues were fixed in LibreOffice.\n","instructions":"After a standard system update you need to restart LibreOffice to make all\nthe necessary changes.\n","references":[],"published":"2015-11-05T15:55:08.822924","description":"Federico Scrinzi discovered that LibreOffice incorrectly handled documents\ninserted into Writer or Calc via links. If a user were tricked into opening\na specially crafted document, a remote attacker could possibly obtain the\ncontents of arbitrary files. (CVE-2015-4551)\n\nIt was discovered that LibreOffice incorrectly handled PrinterSetup data\nstored in ODF files. If a user were tricked into opening a specially\ncrafted ODF document, a remote attacker could cause LibreOffice to crash,\nand possibly execute arbitrary code. (CVE-2015-5212)\n\nIt was discovered that LibreOffice incorrectly handled the number of pieces\nin DOC files. If a user were tricked into opening a specially crafted DOC\ndocument, a remote attacker could cause LibreOffice to crash, and possibly\nexecute arbitrary code. (CVE-2015-5213)\n\nIt was discovered that LibreOffice incorrectly handled bookmarks in DOC\nfiles. If a user were tricked into opening a specially crafted DOC\ndocument, a remote attacker could cause LibreOffice to crash, and possibly\nexecute arbitrary code. (CVE-2015-5214)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libreoffice","version":"1:3.5.7-0ubuntu9","description":"Office productivity suite","is_source":true},{"name":"libreoffice-core","version":"1:3.5.7-0ubuntu9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:3.5.7-0ubuntu9"}],"trusty":[{"name":"libreoffice","version":"1:4.2.8-0ubuntu3","description":"Office productivity suite","is_source":true},{"name":"browser-plugin-libreoffice","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"fonts-opensymbol","version":"2:102.6+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-avmedia-backend-gstreamer","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-base","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-base-core","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-base-drivers","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-calc","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-common","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-core","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-dev","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-dev-doc","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-draw","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-emailmerge","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-gnome","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-gtk","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-gtk3","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-impress","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-java-common","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-kde","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-l10n-in","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-l10n-ku","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-l10n-za","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-librelogo","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-math","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-mysql-connector","version":"1.0.2+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-officebean","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-ogltrans","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-pdfimport","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-presentation-minimizer","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-presenter-console","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-report-builder","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-report-builder-bin","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-script-provider-bsh","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-script-provider-js","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-script-provider-python","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-sdbc-firebird","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-sdbc-hsqldb","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-sdbc-postgresql","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-crystal","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-galaxy","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-hicontrast","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-human","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-oxygen","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-sifr","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-tango","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-subsequentcheckbase","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-wiki-publisher","version":"1.1.2+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-writer","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"openoffice.org-dtd-officedocument1.0","version":"2:1.0+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"python3-uno","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"uno-libs3","version":"4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"ure","version":"4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"}],"vivid":[{"name":"libreoffice","version":"1:4.4.6~rc3-0ubuntu1","description":"Office productivity suite","is_source":true},{"name":"libreoffice-core","version":"1:4.4.6~rc3-0ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.4.6~rc3-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2015-4551","CVE-2015-5212","CVE-2015-5213","CVE-2015-5214"]}]},{"id":"CVE-2015-4551","published":"2015-11-03T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nLibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored\nLinkUpdateMode configuration information in OpenDocument Format files and\ntemplates when handling links, which might allow remote attackers to obtain\nsensitive information via a crafted document, which embeds data from local\nfiles into (1) Calc or (2) Writer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/","https://ubuntu.com/security/notices/USN-2793-1","https://www.cve.org/CVERecord?id=CVE-2015-4551"],"bugs":[""],"patches":{"libreoffice":[]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"precise","status":"released","description":"1:3.5.7-0ubuntu9","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.8-0ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:4.4.6~rc3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:5.0.2-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2793-1"],"notices":[{"id":"USN-2793-1","title":"LibreOffice vulnerabilities","summary":"Several security issues were fixed in LibreOffice.\n","instructions":"After a standard system update you need to restart LibreOffice to make all\nthe necessary changes.\n","references":[],"published":"2015-11-05T15:55:08.822924","description":"Federico Scrinzi discovered that LibreOffice incorrectly handled documents\ninserted into Writer or Calc via links. If a user were tricked into opening\na specially crafted document, a remote attacker could possibly obtain the\ncontents of arbitrary files. (CVE-2015-4551)\n\nIt was discovered that LibreOffice incorrectly handled PrinterSetup data\nstored in ODF files. If a user were tricked into opening a specially\ncrafted ODF document, a remote attacker could cause LibreOffice to crash,\nand possibly execute arbitrary code. (CVE-2015-5212)\n\nIt was discovered that LibreOffice incorrectly handled the number of pieces\nin DOC files. If a user were tricked into opening a specially crafted DOC\ndocument, a remote attacker could cause LibreOffice to crash, and possibly\nexecute arbitrary code. (CVE-2015-5213)\n\nIt was discovered that LibreOffice incorrectly handled bookmarks in DOC\nfiles. If a user were tricked into opening a specially crafted DOC\ndocument, a remote attacker could cause LibreOffice to crash, and possibly\nexecute arbitrary code. (CVE-2015-5214)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libreoffice","version":"1:3.5.7-0ubuntu9","description":"Office productivity suite","is_source":true},{"name":"libreoffice-core","version":"1:3.5.7-0ubuntu9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:3.5.7-0ubuntu9"}],"trusty":[{"name":"libreoffice","version":"1:4.2.8-0ubuntu3","description":"Office productivity suite","is_source":true},{"name":"browser-plugin-libreoffice","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"fonts-opensymbol","version":"2:102.6+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-avmedia-backend-gstreamer","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-base","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-base-core","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-base-drivers","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-calc","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-common","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-core","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-dev","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-dev-doc","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-draw","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-emailmerge","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-gnome","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-gtk","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-gtk3","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-impress","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-java-common","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-kde","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-l10n-in","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-l10n-ku","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-l10n-za","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-librelogo","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-math","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-mysql-connector","version":"1.0.2+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-officebean","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-ogltrans","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-pdfimport","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-presentation-minimizer","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-presenter-console","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-report-builder","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-report-builder-bin","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-script-provider-bsh","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-script-provider-js","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-script-provider-python","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-sdbc-firebird","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-sdbc-hsqldb","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-sdbc-postgresql","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-crystal","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-galaxy","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-hicontrast","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-human","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-oxygen","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-sifr","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-style-tango","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-subsequentcheckbase","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-wiki-publisher","version":"1.1.2+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"libreoffice-writer","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"openoffice.org-dtd-officedocument1.0","version":"2:1.0+LibO4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"python3-uno","version":"1:4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"uno-libs3","version":"4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"},{"name":"ure","version":"4.2.8-0ubuntu3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3","pocket":"security"}],"vivid":[{"name":"libreoffice","version":"1:4.4.6~rc3-0ubuntu1","description":"Office productivity suite","is_source":true},{"name":"libreoffice-core","version":"1:4.4.6~rc3-0ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.4.6~rc3-0ubuntu1"}]},"type":"USN","cves_ids":["CVE-2015-4551","CVE-2015-5212","CVE-2015-5213","CVE-2015-5214"]}]},{"id":"CVE-2015-8074","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmediaserver in Android before 5.1.1 LMY48X allows remote attackers to\nobtain sensitive information, and consequently bypass an unspecified\nprotection mechanism, via unknown vectors, aka internal bugs 23540907 and\n23515142, a different vulnerability than CVE-2015-6611.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"as with previous stagefright issues, this issue affects Ubuntu's\nandroid packages, but not in a way that is exposed to apps. See\nCVE-2015-1538 for details"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-8074"],"bugs":[""],"patches":{"android":[]},"tags":{"android":["apparmor"]},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8073","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption) via a crafted media file, aka internal bug 14388161, a\ndifferent vulnerability than CVE-2015-6608 and CVE-2015-8072.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"as with previous stagefright issues, this issue affects Ubuntu's\nandroid packages, but not in a way that is exposed to apps. See\nCVE-2015-1538 for details"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-8073"],"bugs":[""],"patches":{"android":[]},"tags":{"android":["apparmor"]},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8072","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before\n2015-11-01 allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via a crafted media file, aka\ninternal bug 23881715, a different vulnerability than CVE-2015-6608 and\nCVE-2015-8073.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"as with previous stagefright issues, this issue affects Ubuntu's\nandroid packages, but not in a way that is exposed to apps. See\nCVE-2015-1538 for details"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-8072"],"bugs":[""],"patches":{"android":[]},"tags":{"android":["apparmor"]},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6614","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nTelephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain\nprivileges, and consequently bypass intended network-interface\nrestrictions, perform expensive data transfers, or cause a denial of\nservice (call-reception outage or mute manipulation), via a crafted\napplication, aka internal bug 21900139.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu does not use the Android Telephony stack and implements its\nown access controls for rild"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-6614"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6613","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows\nattackers to send commands to a debugging port, and consequently gain\nprivileges, via a crafted application, as demonstrated by obtaining\nSignature or SignatureOrSystem access, aka internal bug 24371736.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu does not use the Android bluetooth stack"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-6613"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6612","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows\nattackers to gain privileges via a crafted application, aka internal bug\n23540426.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-6612"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6611","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows\nremote attackers to obtain sensitive information, and consequently bypass\nan unspecified protection mechanism, via unknown vectors, aka internal bugs\n23905951, 23912202, 23953967, 23696300, 23600291, 23756261, 23541506,\n23284974, 23542351, and 23542352, a different vulnerability than\nCVE-2015-8074.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"as with previous stagefright issues, this issue affects Ubuntu's\nandroid packages, but not in a way that is exposed to apps. See\nCVE-2015-1538 for details"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-6611"],"bugs":[""],"patches":{"android":[]},"tags":{"android":["apparmor"]},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6610","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01\nallows attackers to gain privileges or cause a denial of service (memory\ncorruption) via a crafted application, aka internal bug 23707088.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"as with previous stagefright issues, this issue affects Ubuntu's\nandroid packages, but not in a way that is exposed to apps. See\nCVE-2015-1538 for details"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-6610"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6609","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption) via a crafted audio file, aka internal bug 22953624.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-6609"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6608","published":"2015-11-03T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01\nallows remote attackers to execute arbitrary code or cause a denial of\nservice (memory corruption) via a crafted media file, aka internal bugs\n19779574, 23680780, 23876444, and 23658148, a different vulnerability than\nCVE-2015-8072 and CVE-2015-8073.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"as with previous stagefright issues, this issue affects Ubuntu's\nandroid packages, but not in a way that is exposed to apps. See\nCVE-2015-1538 for details"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=android-security-updates/n1aw2MGce4E/jhpVEWDUCAAJ","https://www.cve.org/CVERecord?id=CVE-2015-6608"],"bugs":[""],"patches":{"android":[]},"tags":{"android":["apparmor"]},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1 LMY48X","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8036","published":"2015-11-02T19:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before\n1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of\nservice (client crash) and possibly execute arbitrary code via a long\nsession ticket name to the session ticket extension, which is not properly\nhandled when creating a ClientHello message to resume a session. NOTE:\nthis identifier was SPLIT from CVE-2015-5291 per ADT3 due to different\naffected version ranges.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2015-01","https://guidovranken.wordpress.com/2015/10/07/cve-2015-5291/","https://guidovranken.files.wordpress.com/2015/10/cve-2015-5291.pdf","http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169625.html","https://www.cve.org/CVERecord?id=CVE-2015-8036"],"bugs":[""],"patches":{"polarssl":[],"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"}]},{"name":"polarssl","source":"https://ubuntu.com/security/cve?package=polarssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=polarssl","debian":"https://tracker.debian.org/pkg/polarssl","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.3.9-2.1+deb8u1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5470","published":"2015-11-02T19:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe label decompression functionality in PowerDNS Recursor before 3.6.4 and\n3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x\nbefore 3.4.5 allows remote attackers to cause a denial of service (CPU\nconsumption or crash) via a request with a long name that refers to itself.\n NOTE: this vulnerability exists because of an incomplete fix for\nCVE-2015-1868.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"incomplete fix for CVE-2015-1868\nonly affected pdns 3.2+ and pdns-recursor 3.5+"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/07/07/6","https://doc.powerdns.com/md/security/powerdns-advisory-2015-01/","http://downloads.powerdns.com/patches/2015-01/","https://www.cve.org/CVERecord?id=CVE-2015-5470"],"bugs":[""],"patches":{"pdns":[],"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns","source":"https://ubuntu.com/security/cve?package=pdns","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns","debian":"https://tracker.debian.org/pkg/pdns","statuses":[{"release_codename":"artful","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.0-1.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"artful","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.3-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.5.3-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"3.6.2-2+deb8u2build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.7.3-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5291","published":"2015-11-02T19:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS\n(formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote\nSSL servers to cause a denial of service (client crash) and possibly\nexecute arbitrary code via a long hostname to the server name indication\n(SNI) extension, which is not properly handled when creating a ClientHello\nmessage. NOTE: this identifier has been SPLIT per ADT3 due to different\naffected version ranges. See CVE-2015-8036 for the session ticket issue\nthat was introduced in 1.3.0.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"polarssl now known as mbed"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2015-01","https://www.cve.org/CVERecord?id=CVE-2015-5291"],"bugs":[""],"patches":{"polarssl":[],"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.2-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.2.1-2","component":null,"pocket":"security"}]},{"name":"polarssl","source":"https://ubuntu.com/security/cve?package=polarssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=polarssl","debian":"https://tracker.debian.org/pkg/polarssl","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.17, 1.3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.3.9-2.1+deb8u1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8035","published":"2015-11-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect\ncompression errors, which allows context-dependent attackers to cause a\ndenial of service (process hang) via crafted XML data.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"The test xz file does not trigger the DoS in our 2.9.2 builds.\nxz support was accidentally disabled in 2.9.2. Marking the devel release\nas 'needed' so that the build system fix\n(18b8988511b0954272cac4d6c3e6724f9dbf6e0a) doesn't slip in without this\nCVE fix."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/11/02/2","https://ubuntu.com/security/notices/USN-2812-1","https://www.cve.org/CVERecord?id=CVE-2015-8035"],"bugs":["https://bugzilla.gnome.org/show_bug.cgi?id=757466"],"patches":{"libxml2":["upstream: https://git.gnome.org/browse/libxml2/commit/?id=f0709e3ca8f8947f2d91ed34e92e38a4c23eae63"]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"precise","status":"not-affected","description":"xz support not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.9.1+dfsg1-3ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"xz support disabled","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"xz support disabled","component":null,"pocket":"security"}]}],"notices_ids":["USN-2812-1"],"notices":[{"id":"USN-2812-1","title":"libxml2 vulnerabilities","summary":"Several security issues were fixed in libxml2.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2015-11-16T18:19:52.118524","description":"Florian Weimer discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause resource consumption,\nresulting in a denial of service. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-1819)\n\nMichal Zalewski discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-7941)\n\nKostya Serebryany discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7942)\n\nGustavo Grieco discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2015-8035)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.12","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.12"}],"trusty":[{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-dev","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-doc","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-udeb","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-utils","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"python-libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"}],"vivid":[{"name":"libxml2","version":"2.9.2+dfsg1-3ubuntu0.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.2+dfsg1-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.2+dfsg1-3ubuntu0.1"}],"wily":[{"name":"libxml2","version":"2.9.2+zdfsg1-4ubuntu0.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.2+zdfsg1-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.2+zdfsg1-4ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-1819","CVE-2015-7941","CVE-2015-7942","CVE-2015-8035"]}]},{"id":"CVE-2015-5667","published":"2015-10-31T04:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the HTML-Scrubber module before\n0.15 for Perl, when the comment feature is enabled, allows remote attackers\nto inject arbitrary web script or HTML via a crafted comment.","ubuntu_description":"\nIt was discovered that the Perl HTML-Scrubber module incorrectly handles\ncomments. An attacker could possibly use this to execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://metacpan.org/release/HTML-Scrubber","http://jvndb.jvn.jp/jvndb/JVNDB-2015-000171","http://jvn.jp/en/jp/JVN53973084/index.html","https://www.cve.org/CVERecord?id=CVE-2015-5667"],"bugs":[""],"patches":{"libhtml-scrubber-perl":["upstream: https://github.com/nigelm/html-scrubber/commit/e1978cc37867e85c06a84a4651745235010cd6cd"]},"tags":{},"packages":[{"name":"libhtml-scrubber-perl","source":"https://ubuntu.com/security/cve?package=libhtml-scrubber-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libhtml-scrubber-perl","debian":"https://tracker.debian.org/pkg/libhtml-scrubber-perl","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.15-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.11-1+deb8u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.15-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.15-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"0.15-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.15-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7972","published":"2015-10-30T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2)\nlibxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through\n4.6.x do not properly calculate the balloon size when using the\npopulate-on-demand (PoD) system, which allows local HVM guest users to\ncause a denial of service (guest crash) via unspecified vectors related to\n\"heavy memory pressure.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xen.org/xsa/advisory-153.html","https://www.cve.org/CVERecord?id=CVE-2015-7972"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"precise","status":"released","description":"4.1.6.1-0ubuntu0.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4.5.0-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.5.1-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7971","published":"2015-10-30T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXen 3.2.x through 4.6.x does not limit the number of printk console\nmessages when logging certain pmu and profiling hypercalls, which allows\nlocal guests to cause a denial of service via a sequence of crafted (1)\nHYPERCALL_xenoprof_op hypercalls, which are not properly handled in the\ndo_xenoprof_op function in common/xenoprof.c, or (2) HYPERVISOR_xenpmu_op\nhypercalls, which are not properly handled in the do_xenpmu_op function in\narch/x86/cpu/vpmu.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xen.org/xsa/advisory-152.html","https://www.cve.org/CVERecord?id=CVE-2015-7971"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"precise","status":"released","description":"4.1.6.1-0ubuntu0.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4.5.0-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.5.1-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7970","published":"2015-10-30T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x,\n3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest\nadministrators to cause a denial of service (CPU consumption and possibly\nreboot) via crafted memory contents that triggers a \"time-consuming linear\nscan,\" related to Populate-on-Demand.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xen.org/xsa/advisory-150.html","https://www.cve.org/CVERecord?id=CVE-2015-7970"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"precise","status":"released","description":"4.1.6.1-0ubuntu0.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4.5.0-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.5.1-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":62340,"limit":20,"total_results":79316}