{"cves":[{"id":"CVE-2015-7969","published":"2015-10-30T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple memory leaks in Xen 4.0 through 4.6.x allow local guest\nadministrators or domains with certain permission to cause a denial of\nservice (memory consumption) via a large number of \"teardowns\" of domains\nwith the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus\nhypercall or the xenoprofile state vcpu pointer array allocated using the\n(2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xen.org/xsa/advisory-149.html","http://xenbits.xen.org/xsa/advisory-151.html","https://www.cve.org/CVERecord?id=CVE-2015-7969"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"precise","status":"released","description":"4.1.6.1-0ubuntu0.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4.5.0-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.5.1-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7835","published":"2015-10-30T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does\nnot properly validate level 2 page table entries, which allows local PV\nguest administrators to gain privileges via a crafted superpage mapping.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xen.org/xsa/advisory-148.html","https://www.cve.org/CVERecord?id=CVE-2015-7835"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"precise","status":"released","description":"4.1.6.1-0ubuntu0.12.04.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4.5.0-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.5.1-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7814","published":"2015-10-30T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in the relinquish_memory function in arch/arm/domain.c in\nXen 4.6.x and earlier allows local domains with partial management control\nto cause a denial of service (host crash) via vectors involving the\ndestruction of a domain and using XENMEM_decrease_reservation to reduce the\nmemory of the domain.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xen.org/xsa/advisory-147.html","https://www.cve.org/CVERecord?id=CVE-2015-7814"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"precise","status":"not-affected","description":"4.1.6.1-0ubuntu0.12.04.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4.5.0-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.5.1-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7813","published":"2015-10-30T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXen 4.4.x, 4.5.x, and 4.6.x does not limit the number of printk console\nmessages when reporting unimplemented hypercalls, which allows local guests\nto cause a denial of service via a sequence of (1) HYPERVISOR_physdev_op\nhypercalls, which are not properly handled in the do_physdev_op function in\narch/arm/physdev.c, or (2) HYPERVISOR_hvm_op hypercalls, which are not\nproperly handled in the do_hvm_op function in arch/arm/hvm.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xen.org/xsa/advisory-146.html","https://www.cve.org/CVERecord?id=CVE-2015-7813"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"precise","status":"not-affected","description":"4.1.6.1-0ubuntu0.12.04.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.2-0ubuntu0.14.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4.5.0-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.5.1-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3230","published":"2015-10-29T20:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\n389 Directory Server (formerly Fedora Directory Server) before 1.3.3.12\ndoes not enforce the nsSSL3Ciphers preference when creating an sslSocket,\nwhich allows remote attackers to have unspecified impact by requesting to\nuse a disabled cipher.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"second ticket fixes regression if"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://fedorahosted.org/389/ticket/48194","https://fedorahosted.org/389/ticket/47838","https://www.cve.org/CVERecord?id=CVE-2015-3230"],"bugs":[""],"patches":{"389-ds-base":["upstream: https://fedorahosted.org/389/changeset/99109e38ca671951c50724018fce71e2e362f0ff/","upstream: https://fedorahosted.org/389/changeset/53c9c4e84e3bcbc40de87b1e7cf7634d14599e1c/"]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.4.9-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5292","published":"2015-10-29T16:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMemory leak in the Privilege Attribute Certificate (PAC) responder plugin\n(sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before\n1.13.1 allows remote authenticated users to cause a denial of service\n(memory consumption) via a large number of logins that trigger parsing of\nPAC blobs during Kerberos authentication.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"according to debian, the responder part is not built, so might\nnot be affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-5292"],"bugs":["https://fedorahosted.org/sssd/ticket/2803"],"patches":{"sssd":["vendor: https://fedorahosted.org/sssd/attachment/ticket/2803/0001-Fix-memory-leak-in-sssdpac_verify.patch","upstream: https://git.fedorahosted.org/cgit/sssd.git/commit/?id=b4c44ebb8997d3debb33607c123ccfd9926e0cba"]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.13.1-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.13.1-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.13.1-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.13.1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.13.1-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.13.1-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.13.1-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8025","published":"2015-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ndriver/subprocs.c in XScreenSaver before 5.34 does not properly perform an\ninternal consistency check, which allows physically proximate attackers to\nbypass the lock screen by hot swapping monitors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.jwz.org/blog/2015/10/xscreensaver-5-34/","https://ubuntu.com/security/notices/USN-2789-1","https://www.cve.org/CVERecord?id=CVE-2015-8025"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802914","https://bugzilla.redhat.com/show_bug.cgi?id=1274452"],"patches":{"xscreensaver":["vendor: http://pkgs.fedoraproject.org/cgit/xscreensaver.git/plain/xscreensaver-5.33-0002-Modify-sigchld_hander-in_signal_hander_p-mechanism.patch?id"]},"tags":{},"packages":[{"name":"xscreensaver","source":"https://ubuntu.com/security/cve?package=xscreensaver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xscreensaver","debian":"https://tracker.debian.org/pkg/xscreensaver","statuses":[{"release_codename":"precise","status":"released","description":"5.15-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.15-3+deb7u1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.34-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"5.34-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2789-1"],"notices":[{"id":"USN-2789-1","title":"XScreenSaver vulnerability","summary":"The system could be made to expose sensitive information.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2015-11-03T22:55:14.113009","description":"It was discovered that XScreenSaver incorrectly handled unplugging an\nexternal monitor. An attacker with physical access could use this flaw to\ngain access to a locked session.\n","is_hidden":false,"release_packages":{"precise":[{"name":"xscreensaver","version":"5.15-2ubuntu1.1","description":"Automatic screensaver for X","is_source":true},{"name":"xscreensaver","version":"5.15-2ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xscreensaver","version_link":"https://launchpad.net/ubuntu/+source/xscreensaver/5.15-2ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2015-8025"]}]},{"id":"CVE-2015-7713","published":"2015-10-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before\n2015.1.2 (kilo) do not properly apply security group changes, which allows\nremote attackers to bypass intended restriction by leveraging an instance\nthat was running when the change was made.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/10/05/10","http://lists.openstack.org/pipermail/openstack-announce/2015-October/000683.html","https://ubuntu.com/security/notices/USN-3449-1","https://www.cve.org/CVERecord?id=CVE-2015-7713"],"bugs":["https://bugs.launchpad.net/bugs/1491307","https://bugs.launchpad.net/bugs/1484738"],"patches":{"nova":["upstream: https://review.openstack.org/222026","upstream: https://review.openstack.org/222023","upstream: https://review.openstack.org/222022"]},"tags":{},"packages":[{"name":"nova","source":"https://ubuntu.com/security/cve?package=nova","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nova","debian":"https://tracker.debian.org/pkg/nova","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:2014.1.5-0ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:2015.1.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3449-1"],"notices":[{"id":"USN-3449-1","title":"OpenStack Nova vulnerabilities","summary":"Several security issues were fixed in OpenStack Nova.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-10-11T11:46:58.095064","description":"George Shuklin discovered that OpenStack Nova incorrectly handled the\nmigration process. A remote authenticated user could use this issue to\nconsume resources, resulting in a denial of service. (CVE-2015-3241)\n\nGeorge Shuklin and Tushar Patil discovered that OpenStack Nova incorrectly\nhandled deleting instances. A remote authenticated user could use this\nissue to consume disk resources, resulting in a denial of service.\n(CVE-2015-3280)\n\nIt was discovered that OpenStack Nova incorrectly limited qemu-img calls. A\nremote authenticated user could use this issue to consume resources,\nresulting in a denial of service. (CVE-2015-5162)\n\nMatthew Booth discovered that OpenStack Nova incorrectly handled snapshots.\nA remote authenticated user could use this issue to read arbitrary files.\n(CVE-2015-7548)\n\nSreekumar S. and Suntao discovered that OpenStack Nova incorrectly applied\nsecurity group changes. A remote attacker could possibly use this issue to\nbypass intended restriction changes by leveraging an instance that was\nrunning when the change was made. (CVE-2015-7713)\n\nMatt Riedemann discovered that OpenStack Nova incorrectly handled logging.\nA local attacker could possibly use this issue to obtain sensitive\ninformation from log files. (CVE-2015-8749)\n\nMatthew Booth discovered that OpenStack Nova incorrectly handled certain\nqcow2 headers. A remote authenticated user could possibly use this issue to\nread arbitrary files. (CVE-2016-2140)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"nova","version":"1:2014.1.5-0ubuntu1.7","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"nova-ajax-console-proxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-ec2","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-metadata","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-os-compute","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-os-volume","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-baremetal","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-cells","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-cert","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-common","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-kvm","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-libvirt","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-lxc","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-qemu","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-vmware","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-xen","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-conductor","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-console","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-consoleauth","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-doc","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-network","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-novncproxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-objectstore","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-scheduler","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-spiceproxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-volume","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-xvpvncproxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"python-nova","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-3241","CVE-2015-3280","CVE-2015-5162","CVE-2015-7548","CVE-2015-7713","CVE-2015-8749","CVE-2016-2140"]}]},{"id":"CVE-2015-7873","published":"2015-10-28T10:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and\n4.5.x before 4.5.1 allows remote attackers to spoof content via the url\nparameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.phpmyadmin.net/security/PMASA-2015-5/","https://www.cve.org/CVERecord?id=CVE-2015-7873"],"bugs":[""],"patches":{"phpmyadmin":["upstream: https://github.com/phpmyadmin/phpmyadmin/commit/2b31866fe0b30b867aaf5b5fedb11adb354e037f","upstream: https://github.com/phpmyadmin/phpmyadmin/commit/cd097656758f981f80fb9029c7d6b4294582b706"]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"artful","status":"not-affected","description":"4:4.5.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:4.5.1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4:4.5.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4:4.5.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4:4.5.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4:4.5.1-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"4:4.2.12-2+deb8u1build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5240","published":"2015-10-27T16:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in OpenStack Neutron before 2014.2.4 and 2015.1 before\n2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows\nremote authenticated users to bypass IP anti-spoofing controls by changing\nthe device owner of a port to start with network: before the security group\nrules are applied.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"This fix will be included in future 2014.2.4 (juno) and\n2015.1.2 (kilo) releases."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/09/08/9","https://www.cve.org/CVERecord?id=CVE-2015-5240"],"bugs":["https://launchpad.net/bugs/1489111"],"patches":{"neutron":["upstream: https://review.openstack.org/221345","upstream: https://review.openstack.org/221344","upstream: https://review.openstack.org/221342"]},"tags":{},"packages":[{"name":"neutron","source":"https://ubuntu.com/security/cve?package=neutron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neutron","debian":"https://tracker.debian.org/pkg/neutron","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:2015.1.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2:7.0.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [code not present]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-1341","published":"2015-10-27T00:00:00","updated_at":"2025-08-25T21:34:39.244824+00:00","description":"\nAny Python module in sys.path can be imported if the command line of the\nprocess triggering the coredump is Python and the first argument is -m in\nApport before 2.19.2 function _python_module_path.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2782-1","https://www.cve.org/CVERecord?id=CVE-2015-1341"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1507480"],"patches":{"apport":[]},"tags":{},"packages":[{"name":"apport","source":"https://ubuntu.com/security/cve?package=apport","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apport","debian":"https://tracker.debian.org/pkg/apport","statuses":[{"release_codename":"precise","status":"released","description":"2.0.1-0ubuntu17.13","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.14.1-0ubuntu3.18","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"2.17.2-0ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.19.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.19.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.19.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.19.2-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2782-1"],"notices":[{"id":"USN-2782-1","title":"Apport vulnerability","summary":"Apport could be made to run programs as an administrator.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-10-27T12:36:00.450055","description":"Gabriel Campana discovered that Apport incorrectly handled Python module\nimports. A local attacker could use this issue to elevate privileges.\n","is_hidden":false,"release_packages":{"precise":[{"name":"apport","version":"2.0.1-0ubuntu17.13","description":"automatically generate crash reports for debugging","is_source":true},{"name":"apport","version":"2.0.1-0ubuntu17.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.0.1-0ubuntu17.13"}],"trusty":[{"name":"apport","version":"2.14.1-0ubuntu3.18","description":"automatically generate crash reports for debugging","is_source":true},{"name":"apport","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"apport-gtk","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"apport-kde","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"apport-noui","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"apport-retrace","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"apport-valgrind","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"dh-apport","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"python-apport","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"python-problem-report","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"python3-apport","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"},{"name":"python3-problem-report","version":"2.14.1-0ubuntu3.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18","pocket":"security"}],"vivid":[{"name":"apport","version":"2.17.2-0ubuntu1.7","description":"automatically generate crash reports for debugging","is_source":true},{"name":"apport","version":"2.17.2-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.17.2-0ubuntu1.7"}],"wily":[{"name":"apport","version":"2.19.1-0ubuntu4","description":"automatically generate crash reports for debugging","is_source":true},{"name":"apport","version":"2.19.1-0ubuntu4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apport","version_link":"https://launchpad.net/ubuntu/+source/apport/2.19.1-0ubuntu4"}]},"type":"USN","cves_ids":["CVE-2015-1341"]}]},{"id":"CVE-2015-3256","published":"2015-10-26T19:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPolicyKit (aka polkit) before 0.113 allows local users to cause a denial of\nservice (memory corruption and polkitd daemon crash) and possibly gain\nprivileges via unspecified vectors, related to \"javascript rule\nevaluation.\"","ubuntu_description":"","notes":[{"author":"sbeattie","note":"likely need all the commits between 2015-06-18 and\n2015-06-19 plus 2015-06-23 to address issues\nnote that this only affected policykit versions that used\njavscript via libmozjs, which none of the ubuntu versions do"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.freedesktop.org/show_bug.cgi?id=69501","https://bugzilla.redhat.com/show_bug.cgi?id=910262#c75","https://www.cve.org/CVERecord?id=CVE-2015-3256"],"bugs":[""],"patches":{"policykit-1":["upstream: http://cgit.freedesktop.org/polkit/commit/?id=9f5e0c731784003bd4d6fc75ab739ff8b2ea269f"]},"tags":{},"packages":[{"name":"policykit-1","source":"https://ubuntu.com/security/cve?package=policykit-1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=policykit-1","debian":"https://tracker.debian.org/pkg/policykit-1","statuses":[{"release_codename":"precise","status":"not-affected","description":"no libmozjs","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"no libmozjs","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"no libmozjs","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.113","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-8242","published":"2015-10-26T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibrsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which\nmakes it easier for remote attackers to modify transmitted data via a\nbirthday attack.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"Too intrusive to backport"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/10/12","https://www.cve.org/CVERecord?id=CVE-2014-8242"],"bugs":["https://github.com/librsync/librsync/issues/5"],"patches":{"librsync":[]},"tags":{},"packages":[{"name":"librsync","source":"https://ubuntu.com/security/cve?package=librsync","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=librsync","debian":"https://tracker.debian.org/pkg/librsync","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.0.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7699","published":"2015-10-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7,\nand 8.1.x before 8.1.2 allows remote authenticated users to instantiate\narbitrary classes and possibly execute arbitrary code via a crafted mount\npoint option, related to \"objectstore.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"owncloud packages in Ubuntu are now empty"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://owncloud.org/security/advisory/?id=oc-sa-2015-018","https://www.cve.org/CVERecord?id=CVE-2015-7699"],"bugs":[""],"patches":{"owncloud":["upstream: https://github.com/owncloud/core/commit/b05e178bbf884b120d1106e6a28f35aa50d6d06f"]},"tags":{},"packages":[{"name":"owncloud","source":"https://ubuntu.com/security/cve?package=owncloud","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=owncloud","debian":"https://tracker.debian.org/pkg/owncloud","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.9~dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7298","published":"2015-10-26T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nownCloud Desktop Client before 2.0.1, when compiled with a Qt release after\n5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors\nto be ignored, which makes it easier for remote attackers to conduct\nman-in-the-middle (MITM) attacks by leveraging a server using a self-signed\ncertificate. NOTE: this vulnerability exists because of a partial\nCVE-2015-4456 regression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://owncloud.org/security/advisory/?id=oc-sa-2015-016","https://www.cve.org/CVERecord?id=CVE-2015-7298"],"bugs":[""],"patches":{"owncloud-client":[]},"tags":{},"packages":[{"name":"owncloud-client","source":"https://ubuntu.com/security/cve?package=owncloud-client","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=owncloud-client","debian":"https://tracker.debian.org/pkg/owncloud-client","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.1.1+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.1.1+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.1.1+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [compiled with qt4]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6670","published":"2015-10-26T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1\ndoes not properly check ownership of calendars, which allows remote\nauthenticated users to read arbitrary calendars via the calid parameter to\napps/calendar/export.php.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"owncloud packages in Ubuntu are now empty"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://owncloud.org/security/advisory/?id=oc-sa-2015-015","https://www.cve.org/CVERecord?id=CVE-2015-6670"],"bugs":[""],"patches":{"owncloud":[]},"tags":{},"packages":[{"name":"owncloud","source":"https://ubuntu.com/security/cve?package=owncloud","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=owncloud","debian":"https://tracker.debian.org/pkg/owncloud","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.8~dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6500","published":"2015-10-26T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x\nbefore 8.1.1 allows remote authenticated users to list directory contents\nand possibly cause a denial of service (CPU consumption) via a .. (dot dot)\nin the dir parameter to index.php/apps/files/ajax/scan.php.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"owncloud packages in Ubuntu are now empty"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://owncloud.org/security/advisory/?id=oc-sa-2015-014","https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2015-048.txt","https://github.com/owncloud/core/commit/9f8c0a3a8d14f1c127b2034faa14d8d309f962e9","https://www.cve.org/CVERecord?id=CVE-2015-6500"],"bugs":[""],"patches":{"owncloud":[]},"tags":{},"packages":[{"name":"owncloud","source":"https://ubuntu.com/security/cve?package=owncloud","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=owncloud","debian":"https://tracker.debian.org/pkg/owncloud","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.1.1, 8.0.6","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4456","published":"2015-10-26T14:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nownCloud Desktop Client before 1.8.2 does not call\nQNetworkReply::ignoreSslErrors with the list of errors to be ignored, which\nallows man-in-the-middle attackers to bypass the user's certificate\ndistrust decision and obtain sensitive information by leveraging a\nself-signed certificate and a connection to a server using its own\nself-signed certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://owncloud.org/security/advisory/?id=oc-sa-2015-009","https://owncloud.org/security/advisories/improper-validation-of-certificates-when-using-self-signed-certificates/","https://www.cve.org/CVERecord?id=CVE-2015-4456"],"bugs":[""],"patches":{"owncloud-client":[]},"tags":{},"packages":[{"name":"owncloud-client","source":"https://ubuntu.com/security/cve?package=owncloud-client","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=owncloud-client","debian":"https://tracker.debian.org/pkg/owncloud-client","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.1.1+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.1.1+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.1.1+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.7.0~beta1+really1.6.4+dfsg-1+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.1.1+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7981","published":"2015-10-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64,\n1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to\nobtain sensitive process memory information via crafted tIME chunk data in\nan image file, which triggers an out-of-bounds read.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2815-1","https://www.cve.org/CVERecord?id=CVE-2015-7981"],"bugs":["http://sourceforge.net/p/libpng/bugs/241/","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=803078"],"patches":{"libpng":["upstream: http://sourceforge.net/p/libpng/code/ci/fbf0f024346ca0a4ffc64b082a95c6b6bb6d29c4/"],"firefox":[],"thunderbird":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"not-affected","description":"uses system libpng","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"uses system libpng","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"uses system libpng","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [uses system libpng]]","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"bundles libpng 1.6.18","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [bundles libpng 1.6.18]]","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"precise","status":"released","description":"1.2.46-3ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.2.50-1ubuntu2.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.54beta01","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.2.51-0ubuntu3.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.2.51-0ubuntu3.15.10.1","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"precise","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"bundles libpng 1.6.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [bundles libpng 1.6.16]]","component":null,"pocket":"security"}]}],"notices_ids":["USN-2815-1"],"notices":[{"id":"USN-2815-1","title":"libpng vulnerabilities","summary":"libpng could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2015-11-19T19:01:30.819998","description":"Mikulas Patocka discovered that libpng incorrectly handled certain large\nfields. If a user or automated system using libpng were tricked into\nopening a specially crafted image, an attacker could exploit this to cause\nlibpng to crash, leading to a denial of service. This issue only affected\nUbuntu 12.04 LTS. (CVE-2012-3425)\n\nQixue Xiao discovered that libpng incorrectly handled certain time values.\nIf a user or automated system using libpng were tricked into opening a\nspecially crafted image, an attacker could exploit this to cause libpng to\ncrash, leading to a denial of service. (CVE-2015-7981)\n\nIt was discovered that libpng incorrectly handled certain small bit-depth\nvalues. If a user or automated system using libpng were tricked into\nopening a specially crafted image, an attacker could exploit this to cause\na denial of service or execute code with the privileges of the user\ninvoking the program. (CVE-2015-8126)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libpng","version":"1.2.46-3ubuntu4.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.46-3ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.46-3ubuntu4.1"}],"trusty":[{"name":"libpng","version":"1.2.50-1ubuntu2.14.04.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.50-1ubuntu2.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.1","pocket":"security"},{"name":"libpng12-0-udeb","version":"1.2.50-1ubuntu2.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.1","pocket":"security"},{"name":"libpng12-dev","version":"1.2.50-1ubuntu2.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.1","pocket":"security"},{"name":"libpng3","version":"1.2.50-1ubuntu2.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.50-1ubuntu2.14.04.1","pocket":"security"}],"vivid":[{"name":"libpng","version":"1.2.51-0ubuntu3.15.04.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.51-0ubuntu3.15.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.51-0ubuntu3.15.04.1"}],"wily":[{"name":"libpng","version":"1.2.51-0ubuntu3.15.10.1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.51-0ubuntu3.15.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":"https://launchpad.net/ubuntu/+source/libpng/1.2.51-0ubuntu3.15.10.1"}]},"type":"USN","cves_ids":["CVE-2012-3425","CVE-2015-7981","CVE-2015-8126"]}]},{"id":"CVE-2015-5286","published":"2015-10-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before\n2015.1.2 (kilo) allows remote authenticated users to bypass the storage\nquota and cause a denial of service (disk consumption) by deleting images\nthat are being uploaded using a token that expires during the process.\nNOTE: this vulnerability exists because of an incomplete fix for\nCVE-2014-9623.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://security.openstack.org/ossa/OSSA-2015-020.html","http://lists.openstack.org/pipermail/openstack-announce/2015-October/000668.html","https://ubuntu.com/security/notices/USN-3446-1","https://www.cve.org/CVERecord?id=CVE-2015-5286"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=800741","https://bugs.launchpad.net/glance/+bug/1498163"],"patches":{"glance":["upstream: https://review.openstack.org/229946","upstream: https://review.openstack.org/229975","upstream: https://review.openstack.org/229945","upstream: https://review.openstack.org/229973","upstream: https://review.openstack.org/230056","upstream: https://review.openstack.org/229972","upstream: https://review.openstack.org/229943","upstream: https://review.openstack.org/229971","vendor: http://ftp.redhat.com/pub/redhat/linux/enterprise/7Server/en/RHOS/SRPMS/openstack-glance-2014.1.5-5.el7ost.src.rpm"]},"tags":{},"packages":[{"name":"glance","source":"https://ubuntu.com/security/cve?package=glance","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glance","debian":"https://tracker.debian.org/pkg/glance","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:2014.1.5-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:2015.1.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2:11.0.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:11.0.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2:11.0.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2:11.0.0-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3446-1"],"notices":[{"id":"USN-3446-1","title":"OpenStack Glance vulnerabilities","summary":"Several security issues were fixed in OpenStack Glance.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-10-11T11:24:42.523802","description":"Hemanth Makkapati discovered that OpenStack Glance incorrectly handled\naccess restrictions. A remote authenticated user could use this issue to\nchange the status of images, contrary to access restrictions.\n(CVE-2015-5251)\n\nMike Fedosin and Alexei Galkin discovered that OpenStack Glance incorrectly\nhandled the storage quota. A remote authenticated user could use this issue\nto consume disk resources, leading to a denial of service. (CVE-2015-5286)\n\nErno Kuvaja discovered that OpenStack Glance incorrectly handled the\nshow_multiple_locations option. When show_multiple_locations is enabled,\na remote authenticated user could change an image status and upload new\nimage data. (CVE-2016-0757)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"glance","version":"1:2014.1.5-0ubuntu1.1","description":"OpenStack Image Registry and Delivery Service","is_source":true},{"name":"glance","version":"1:2014.1.5-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glance","version_link":"https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1","pocket":"security"},{"name":"glance-api","version":"1:2014.1.5-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glance","version_link":"https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1","pocket":"security"},{"name":"glance-common","version":"1:2014.1.5-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glance","version_link":"https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1","pocket":"security"},{"name":"glance-registry","version":"1:2014.1.5-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glance","version_link":"https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1","pocket":"security"},{"name":"python-glance","version":"1:2014.1.5-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glance","version_link":"https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1","pocket":"security"},{"name":"python-glance-doc","version":"1:2014.1.5-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glance","version_link":"https://launchpad.net/ubuntu/+source/glance/1:2014.1.5-0ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5251","CVE-2015-5286","CVE-2016-0757"]}]}],"offset":62360,"limit":20,"total_results":79316}