{"cves":[{"id":"CVE-2015-5223","published":"2015-10-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain\nsensitive information via a PUT tempurl and a DLO object manifest that\nreferences an object in another container.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Per upstream, fix for 1449212 will not be applied to kilo and\nearlier"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/26/5","https://ubuntu.com/security/notices/USN-3451-1","https://www.cve.org/CVERecord?id=CVE-2015-5223"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=797032","https://launchpad.net/bugs/1453948","https://launchpad.net/bugs/1449212"],"patches":{"swift":["upstream: https://review.openstack.org/217253","upstream: https://review.openstack.org/217254","upstream: https://review.openstack.org/217255","upstream: https://review.openstack.org/217259","upstream: https://review.openstack.org/217260"]},"tags":{},"packages":[{"name":"swift","source":"https://ubuntu.com/security/cve?package=swift","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=swift","debian":"https://tracker.debian.org/pkg/swift","statuses":[{"release_codename":"trusty","status":"released","description":"1.13.1-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.5.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.5.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.5.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.5.0-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3451-1"],"notices":[{"id":"USN-3451-1","title":"OpenStack Swift vulnerabilities","summary":"Several security issues were fixed in OpenStack Swift.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-10-11T12:01:33.028087","description":"It was discovered that OpenStack Swift incorrectly handled tempurls. A\nremote authenticated user in possession of a tempurl key authorized for PUT\ncould retrieve other objects in the same Swift account. (CVE-2015-5223)\n\nRomain Le Disez and Örjan Persson discovered that OpenStack Swift\nincorrectly closed client connections. A remote attacker could possibly use\nthis issue to consume resources, resulting in a denial of service.\n(CVE-2016-0737, CVE-2016-0738)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"swift","version":"1.13.1-0ubuntu1.5","description":"OpenStack distributed virtual object store","is_source":true},{"name":"python-swift","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"},{"name":"swift","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"},{"name":"swift-account","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"},{"name":"swift-container","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"},{"name":"swift-doc","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"},{"name":"swift-object","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"},{"name":"swift-object-expirer","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"},{"name":"swift-proxy","version":"1.13.1-0ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/swift","version_link":"https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.5","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5223","CVE-2016-0737","CVE-2016-0738"]}]},{"id":"CVE-2015-4625","published":"2015-10-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the authentication_agent_new_cookie function in\nPolicyKit (aka polkit) before 0.113 allows local users to gain privileges\nby creating a large number of connections, which triggers the issuance of a\nduplicate cookie value.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.freedesktop.org/archives/polkit-devel/2015-May/000419.html","http://lists.freedesktop.org/archives/polkit-devel/2015-June/000425.html","http://www.openwall.com/lists/oss-security/2015/06/08/3","https://ubuntu.com/security/notices/USN-3717-1","https://www.cve.org/CVERecord?id=CVE-2015-4625"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=90837","https://bugs.freedesktop.org/show_bug.cgi?id=90832","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796134"],"patches":{"policykit-1":["upstream: http://cgit.freedesktop.org/polkit/commit/?id=ea544ffc18405237ccd95d28d7f45afef49aca17","upstream: http://cgit.freedesktop.org/polkit/commit/?id=493aa5dc1d278ab9097110c1262f5229bbaf1766","upstream: http://cgit.freedesktop.org/polkit/commit/?id=fb5076b7c05d01a532d593a4079a29cf2d63a228"]},"tags":{},"packages":[{"name":"policykit-1","source":"https://ubuntu.com/security/cve?package=policykit-1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=policykit-1","debian":"https://tracker.debian.org/pkg/policykit-1","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.105-4ubuntu3.14.04.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3717-1"],"notices":[{"id":"USN-3717-1","title":"PolicyKit vulnerabilities","summary":"Several security issues were fixed in PolicyKit.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2018-07-16T15:17:18.803554","description":"Tavis Ormandy discovered that PolicyKit incorrectly handled certain invalid\nobject paths. A local attacker could possibly use this issue to cause\nPolicyKit to crash, resulting in a denial of service. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2015-3218)\n\nIt was discovered that PolicyKit incorrectly handled certain duplicate\naction IDs. A local attacker could use this issue to cause PolicyKit to\ncrash, resulting in a denial of service, or possibly escalate privileges.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2015-3255)\n\nTavis Ormandy discovered that PolicyKit incorrectly handled duplicate\ncookie values. A local attacker could use this issue to cause PolicyKit to\ncrash, resulting in a denial of service, or possibly escalate privileges.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2015-4625)\n\nMatthias Gerstner discovered that PolicyKit incorrectly checked users. A\nlocal attacker could possibly use this issue to cause authentication\ndialogs to show up for other users, leading to a denial of service or an\ninformation leak. (CVE-2018-1116)\n","is_hidden":false,"release_packages":{"artful":[{"name":"policykit-1","version":"0.105-18ubuntu0.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"libpolkit-backend-1-0","version":"0.105-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-18ubuntu0.1"}],"bionic":[{"name":"policykit-1","version":"0.105-20ubuntu0.18.04.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"policykit-1","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"}],"trusty":[{"name":"policykit-1","version":"0.105-4ubuntu3.14.04.2","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"policykit-1","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"}],"xenial":[{"name":"policykit-1","version":"0.105-14.1ubuntu0.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"policykit-1","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-3218","CVE-2015-3255","CVE-2015-4625","CVE-2018-1116"]}]},{"id":"CVE-2015-3280","published":"2015-10-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before\n2015.1.2 (kilo) does not properly delete instances from compute nodes,\nwhich allows remote authenticated users to cause a denial of service (disk\nconsumption) by deleting instances while in the resize state.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.openstack.org/pipermail/openstack-announce/2015-September/000580.html","https://ubuntu.com/security/notices/USN-3449-1","https://www.cve.org/CVERecord?id=CVE-2015-3280"],"bugs":["https://bugs.launchpad.net/nova/+bug/1392527"],"patches":{"nova":["upstream: https://review.openstack.org/219301","upstream: https://review.openstack.org/219300","upstream: https://review.openstack.org/219299"]},"tags":{},"packages":[{"name":"nova","source":"https://ubuntu.com/security/cve?package=nova","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nova","debian":"https://tracker.debian.org/pkg/nova","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:2014.1.5-0ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:2015.1.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2:12.0.0-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3449-1"],"notices":[{"id":"USN-3449-1","title":"OpenStack Nova vulnerabilities","summary":"Several security issues were fixed in OpenStack Nova.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-10-11T11:46:58.095064","description":"George Shuklin discovered that OpenStack Nova incorrectly handled the\nmigration process. A remote authenticated user could use this issue to\nconsume resources, resulting in a denial of service. (CVE-2015-3241)\n\nGeorge Shuklin and Tushar Patil discovered that OpenStack Nova incorrectly\nhandled deleting instances. A remote authenticated user could use this\nissue to consume disk resources, resulting in a denial of service.\n(CVE-2015-3280)\n\nIt was discovered that OpenStack Nova incorrectly limited qemu-img calls. A\nremote authenticated user could use this issue to consume resources,\nresulting in a denial of service. (CVE-2015-5162)\n\nMatthew Booth discovered that OpenStack Nova incorrectly handled snapshots.\nA remote authenticated user could use this issue to read arbitrary files.\n(CVE-2015-7548)\n\nSreekumar S. and Suntao discovered that OpenStack Nova incorrectly applied\nsecurity group changes. A remote attacker could possibly use this issue to\nbypass intended restriction changes by leveraging an instance that was\nrunning when the change was made. (CVE-2015-7713)\n\nMatt Riedemann discovered that OpenStack Nova incorrectly handled logging.\nA local attacker could possibly use this issue to obtain sensitive\ninformation from log files. (CVE-2015-8749)\n\nMatthew Booth discovered that OpenStack Nova incorrectly handled certain\nqcow2 headers. A remote authenticated user could possibly use this issue to\nread arbitrary files. (CVE-2016-2140)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"nova","version":"1:2014.1.5-0ubuntu1.7","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"nova-ajax-console-proxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-ec2","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-metadata","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-os-compute","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-api-os-volume","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-baremetal","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-cells","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-cert","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-common","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-kvm","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-libvirt","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-lxc","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-qemu","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-vmware","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-compute-xen","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-conductor","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-console","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-consoleauth","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-doc","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-network","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-novncproxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-objectstore","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-scheduler","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-spiceproxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-volume","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"nova-xvpvncproxy","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"},{"name":"python-nova","version":"1:2014.1.5-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1.5-0ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-3241","CVE-2015-3280","CVE-2015-5162","CVE-2015-7548","CVE-2015-7713","CVE-2015-8749","CVE-2016-2140"]}]},{"id":"CVE-2015-3255","published":"2015-10-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe polkit_backend_action_pool_init function in\npolkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before\n0.113 might allow local users to gain privileges via duplicate action IDs\nin action descriptions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3717-1","https://ubuntu.com/security/notices/USN-3717-2","https://www.cve.org/CVERecord?id=CVE-2015-3255"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796134","https://bugs.freedesktop.org/show_bug.cgi?id=69501","https://bugs.freedesktop.org/show_bug.cgi?id=83590","https://bugzilla.redhat.com/show_bug.cgi?id=1245673"],"patches":{"policykit-1":["upstream: http://cgit.freedesktop.org/polkit/commit/?id=9f5e0c731784003bd4d6fc75ab739ff8b2ea269f"]},"tags":{},"packages":[{"name":"policykit-1","source":"https://ubuntu.com/security/cve?package=policykit-1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=policykit-1","debian":"https://tracker.debian.org/pkg/policykit-1","statuses":[{"release_codename":"artful","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.105-4ubuntu3.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.105-11ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3717-2","USN-3717-1"],"notices":[{"id":"USN-3717-2","title":"PolicyKit vulnerabilities","summary":"Several security issues were fixed in PolicyKit.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2018-07-17T15:05:18.235224","description":"USN-3717-1 fixed a vulnerability in PolicyKit. This update provides\nthe corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that PolicyKit incorrectly handled certain duplicate\n action IDs. A local attacker could use this issue to cause PolicyKit to\n crash, resulting in a denial of service, or possibly escalate privileges.\n (CVE-2015-3255)\n\n Matthias Gerstner discovered that PolicyKit incorrectly checked users. A\n local attacker could possibly use this issue to cause authentication\n dialogs to show up for other users, leading to a denial of service or an\n information leak. (CVE-2018-1116)\n","is_hidden":false,"release_packages":{"precise":[{"name":"policykit-1","version":"0.104-1ubuntu1.2","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"libpolkit-backend-1-0","version":"0.104-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.104-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2015-3255","CVE-2018-1116"]},{"id":"USN-3717-1","title":"PolicyKit vulnerabilities","summary":"Several security issues were fixed in PolicyKit.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2018-07-16T15:17:18.803554","description":"Tavis Ormandy discovered that PolicyKit incorrectly handled certain invalid\nobject paths. A local attacker could possibly use this issue to cause\nPolicyKit to crash, resulting in a denial of service. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2015-3218)\n\nIt was discovered that PolicyKit incorrectly handled certain duplicate\naction IDs. A local attacker could use this issue to cause PolicyKit to\ncrash, resulting in a denial of service, or possibly escalate privileges.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2015-3255)\n\nTavis Ormandy discovered that PolicyKit incorrectly handled duplicate\ncookie values. A local attacker could use this issue to cause PolicyKit to\ncrash, resulting in a denial of service, or possibly escalate privileges.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2015-4625)\n\nMatthias Gerstner discovered that PolicyKit incorrectly checked users. A\nlocal attacker could possibly use this issue to cause authentication\ndialogs to show up for other users, leading to a denial of service or an\ninformation leak. (CVE-2018-1116)\n","is_hidden":false,"release_packages":{"artful":[{"name":"policykit-1","version":"0.105-18ubuntu0.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"libpolkit-backend-1-0","version":"0.105-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-18ubuntu0.1"}],"bionic":[{"name":"policykit-1","version":"0.105-20ubuntu0.18.04.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"policykit-1","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"}],"trusty":[{"name":"policykit-1","version":"0.105-4ubuntu3.14.04.2","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"policykit-1","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"}],"xenial":[{"name":"policykit-1","version":"0.105-14.1ubuntu0.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"policykit-1","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-3218","CVE-2015-3255","CVE-2015-4625","CVE-2018-1116"]}]},{"id":"CVE-2015-3218","published":"2015-10-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe authentication_agent_new function in\npolkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit)\nbefore 0.113 allows local users to cause a denial of service (NULL pointer\ndereference and polkitd daemon crash) by calling\nRegisterAuthenticationAgent with an invalid object path.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.freedesktop.org/archives/polkit-devel/2015-May/000420.html","https://ubuntu.com/security/notices/USN-3717-1","https://www.cve.org/CVERecord?id=CVE-2015-3218"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=787932","https://bugs.freedesktop.org/show_bug.cgi?id=90829"],"patches":{"policykit-1":["upstream: http://cgit.freedesktop.org/polkit/commit/?id=48e646918efb2bf0b3b505747655726d7869f31c"]},"tags":{},"packages":[{"name":"policykit-1","source":"https://ubuntu.com/security/cve?package=policykit-1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=policykit-1","debian":"https://tracker.debian.org/pkg/policykit-1","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.105-4ubuntu3.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.105-11","component":null,"pocket":"security"}]}],"notices_ids":["USN-3717-1"],"notices":[{"id":"USN-3717-1","title":"PolicyKit vulnerabilities","summary":"Several security issues were fixed in PolicyKit.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2018-07-16T15:17:18.803554","description":"Tavis Ormandy discovered that PolicyKit incorrectly handled certain invalid\nobject paths. A local attacker could possibly use this issue to cause\nPolicyKit to crash, resulting in a denial of service. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2015-3218)\n\nIt was discovered that PolicyKit incorrectly handled certain duplicate\naction IDs. A local attacker could use this issue to cause PolicyKit to\ncrash, resulting in a denial of service, or possibly escalate privileges.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2015-3255)\n\nTavis Ormandy discovered that PolicyKit incorrectly handled duplicate\ncookie values. A local attacker could use this issue to cause PolicyKit to\ncrash, resulting in a denial of service, or possibly escalate privileges.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2015-4625)\n\nMatthias Gerstner discovered that PolicyKit incorrectly checked users. A\nlocal attacker could possibly use this issue to cause authentication\ndialogs to show up for other users, leading to a denial of service or an\ninformation leak. (CVE-2018-1116)\n","is_hidden":false,"release_packages":{"artful":[{"name":"policykit-1","version":"0.105-18ubuntu0.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"libpolkit-backend-1-0","version":"0.105-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-18ubuntu0.1"}],"bionic":[{"name":"policykit-1","version":"0.105-20ubuntu0.18.04.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"policykit-1","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-20ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-20ubuntu0.18.04.1","pocket":"security"}],"trusty":[{"name":"policykit-1","version":"0.105-4ubuntu3.14.04.2","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"policykit-1","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-4ubuntu3.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-4ubuntu3.14.04.2","pocket":"security"}],"xenial":[{"name":"policykit-1","version":"0.105-14.1ubuntu0.1","description":"framework for managing administrative policies and privileges","is_source":true},{"name":"gir1.2-polkit-1.0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-agent-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-agent-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-backend-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-backend-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-gobject-1-0","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"libpolkit-gobject-1-dev","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"policykit-1","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"},{"name":"policykit-1-doc","version":"0.105-14.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/policykit-1","version_link":"https://launchpad.net/ubuntu/+source/policykit-1/0.105-14.1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-3218","CVE-2015-3255","CVE-2015-4625","CVE-2018-1116"]}]},{"id":"CVE-2015-7014","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes\nbefore 12.3.1, allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via a crafted\nweb site, a different vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","https://support.apple.com/HT205377","https://support.apple.com/HT205372","https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-7014"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7013","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1,\nallows remote attackers to execute arbitrary code or cause a denial of\nservice (memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205377","https://support.apple.com/HT205372","http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","https://www.cve.org/CVERecord?id=CVE-2015-7013"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7012","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes\nbefore 12.3.1, allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via a crafted\nweb site, a different vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","https://support.apple.com/HT205377","https://support.apple.com/HT205372","https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-7012"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7011","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1,\nallows remote attackers to execute arbitrary code or cause a denial of\nservice (memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205377","https://support.apple.com/HT205372","http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","https://www.cve.org/CVERecord?id=CVE-2015-7011"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7002","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes\nbefore 12.3.1, allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via a crafted\nweb site, a different vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205377","https://support.apple.com/HT205372","https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-7002"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6984","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibarchive in Apple OS X before 10.11.1 allows attackers to write to\narbitrary files via a crafted app that conducts an unspecified symlink\nattack.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no details, likely apple-specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205375","http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html","https://www.cve.org/CVERecord?id=CVE-2015-6984"],"bugs":[""],"patches":{"libarchive":[]},"tags":{},"packages":[{"name":"libarchive","source":"https://ubuntu.com/security/cve?package=libarchive","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libarchive","debian":"https://tracker.debian.org/pkg/libarchive","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5931","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1,\nallows remote attackers to execute arbitrary code or cause a denial of\nservice (memory corruption and application crash) via a crafted web site, a\ndifferent vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-3 and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205377","https://support.apple.com/HT205372","http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","https://www.cve.org/CVERecord?id=CVE-2015-5931"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5930","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes\nbefore 12.3.1, allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via a crafted\nweb site, a different vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","https://support.apple.com/HT205377","https://support.apple.com/HT205372","https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-5930"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5929","published":"2015-10-23T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes\nbefore 12.3.1, allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via a crafted\nweb site, a different vulnerability than other WebKit CVEs listed in\nAPPLE-SA-2015-10-21-1, APPLE-SA-2015-10-21-3, and APPLE-SA-2015-10-21-5.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.apple.com/archives/security-announce/2015/Oct/msg00006.html","https://support.apple.com/HT205377","https://support.apple.com/HT205372","https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00004.html","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-5929"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7005","published":"2015-10-23T10:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-10-21-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-7005"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6982","published":"2015-10-23T10:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-10-21-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-6982"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6981","published":"2015-10-23T10:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 9.1, allows remote attackers to execute\narbitrary code or cause a denial of service (memory corruption and\napplication crash) via a crafted web site, a different vulnerability than\nother WebKit CVEs listed in APPLE-SA-2015-10-21-1.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://support.apple.com/HT205370","http://lists.apple.com/archives/security-announce/2015/Oct/msg00002.html","https://www.cve.org/CVERecord?id=CVE-2015-6981"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7942","published":"2015-10-23T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe xmlParseConditionalSections function in parser.c in libxml2 does not\nproperly skip intermediary entities when it stops parsing invalid input,\nwhich allows context-dependent attackers to cause a denial of service\n(out-of-bounds read and crash) via crafted XML data, a different\nvulnerability than CVE-2015-7941.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2812-1","https://www.cve.org/CVERecord?id=CVE-2015-7942"],"bugs":["https://bugzilla.gnome.org/show_bug.cgi?id=756456","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802827"],"patches":{"libxml2":["upstream: https://git.gnome.org/browse/libxml2/commit/?id=bd0526e66a56e75a18da8c15c4750db8f801c52d","upstream: https://git.gnome.org/browse/libxml2/commit/?id=41ac9049a27f52e7a1f3b341f8714149fc88d450"]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"vivid","status":"released","description":"2.9.2+dfsg1-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.8.dfsg-5.1ubuntu4.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.9.1+dfsg1-3ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.2+really2.9.1+dfsg1-0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.9.2+zdfsg1-4ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2812-1"],"notices":[{"id":"USN-2812-1","title":"libxml2 vulnerabilities","summary":"Several security issues were fixed in libxml2.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2015-11-16T18:19:52.118524","description":"Florian Weimer discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause resource consumption,\nresulting in a denial of service. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-1819)\n\nMichal Zalewski discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-7941)\n\nKostya Serebryany discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7942)\n\nGustavo Grieco discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2015-8035)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.12","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.12"}],"trusty":[{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-dev","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-doc","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-udeb","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-utils","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"python-libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"}],"vivid":[{"name":"libxml2","version":"2.9.2+dfsg1-3ubuntu0.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.2+dfsg1-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.2+dfsg1-3ubuntu0.1"}],"wily":[{"name":"libxml2","version":"2.9.2+zdfsg1-4ubuntu0.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.2+zdfsg1-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.2+zdfsg1-4ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-1819","CVE-2015-7941","CVE-2015-7942","CVE-2015-8035"]}]},{"id":"CVE-2015-7941","published":"2015-10-23T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibxml2 2.9.2 does not properly stop parsing invalid input, which allows\ncontext-dependent attackers to cause a denial of service (out-of-bounds\nread and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl\nor (2) xmlParseConditionalSections function in parser.c, as demonstrated by\nnon-terminated entities.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/04/19/5","http://www.openwall.com/lists/oss-security/2015/10/22/5","https://ubuntu.com/security/notices/USN-2812-1","https://www.cve.org/CVERecord?id=CVE-2015-7941"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=783010","https://bugzilla.gnome.org/show_bug.cgi?id=744980"],"patches":{"libxml2":["upstream: https://git.gnome.org/browse/libxml2/commit/?id=a7dfab7411cbf545f359dd3157e5df1eb0e7ce31","upstream: https://git.gnome.org/browse/libxml2/commit/?id=9b8512337d14c8ddf662fcb98b0135f225a1c489"]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"vivid","status":"released","description":"2.9.2+dfsg1-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.8.dfsg-5.1ubuntu4.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.9.1+dfsg1-3ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.2+really2.9.1+dfsg1-0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.9.2+zdfsg1-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-2812-1"],"notices":[{"id":"USN-2812-1","title":"libxml2 vulnerabilities","summary":"Several security issues were fixed in libxml2.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2015-11-16T18:19:52.118524","description":"Florian Weimer discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause resource consumption,\nresulting in a denial of service. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-1819)\n\nMichal Zalewski discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-7941)\n\nKostya Serebryany discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7942)\n\nGustavo Grieco discovered that libxml2 incorrectly handled certain XML\ndata. If a user or automated system were tricked into opening a specially\ncrafted document, an attacker could possibly cause libxml2 to crash,\nresulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2015-8035)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.12","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.12"}],"trusty":[{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-dev","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-doc","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-udeb","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"libxml2-utils","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"},{"name":"python-libxml2","version":"2.9.1+dfsg1-3ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.5","pocket":"security"}],"vivid":[{"name":"libxml2","version":"2.9.2+dfsg1-3ubuntu0.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.2+dfsg1-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.2+dfsg1-3ubuntu0.1"}],"wily":[{"name":"libxml2","version":"2.9.2+zdfsg1-4ubuntu0.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.2+zdfsg1-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.2+zdfsg1-4ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-1819","CVE-2015-7941","CVE-2015-7942","CVE-2015-8035"]}]},{"id":"CVE-2015-7885","published":"2015-10-23T00:00:00","updated_at":"2026-07-04T07:39:58.897995+00:00","description":"\nThe dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the\nLinux kernel through 4.3.3 does not initialize a certain structure member,\nwhich allows local users to obtain sensitive information from kernel memory\nvia a crafted application.","ubuntu_description":"\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel.","notes":[{"author":"jdstrand","note":"android kernels (flo, goldfish, grouper, maguro, mako and manta) are\nnot supported on the Ubuntu Touch 14.10 and earlier preview kernels\nlinux-lts-saucy no longer receives official support\nlinux-lts-quantal no longer receives official support"}],"codename":null,"priority":"low","cvss3":2.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["http://git.kernel.org/cgit/linux/kernel/git/next/linux-next.git/commit/?id=4b6184336ebb5c8dc1eae7f7ab46ee608a748b05","https://ubuntu.com/security/notices/USN-2841-2","https://ubuntu.com/security/notices/USN-2841-1","https://ubuntu.com/security/notices/USN-2843-1","https://ubuntu.com/security/notices/USN-2842-1","https://ubuntu.com/security/notices/USN-2842-2","https://ubuntu.com/security/notices/USN-2844-1","https://ubuntu.com/security/notices/USN-2843-2","https://ubuntu.com/security/notices/USN-2843-3","https://www.cve.org/CVERecord?id=CVE-2015-7885"],"bugs":["https://launchpad.net/bugs/1509565"],"patches":{"linux":["break-fix: 0b99d58902dd82fa51216eb8e0d6ddd8c43e90e4 4b6184336ebb5c8dc1eae7f7ab46ee608a748b05"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-73.116","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"3.19.0-41.46","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.2.0-21.25","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.3.0-1.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"precise","status":"released","description":"3.13.0-73.116~precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.16.0-56.75~14.04.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.19.0-41.46~14.04.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.2.0-21.25~14.04.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"4.2.0-1016.23","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.3.0-1006.6","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2843-2","USN-2842-2","USN-2844-1","USN-2841-1","USN-2841-2","USN-2842-1","USN-2843-1","USN-2843-3"],"notices":[{"id":"USN-2843-2","title":"Linux kernel (Wily HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T19:24:07.841819","description":"Jan Beulich discovered that the KVM svm hypervisor implementation in the\nLinux kernel did not properly catch Debug exceptions on AMD processors. An\nattacker in a guest virtual machine could use this to cause a denial of\nservice (system crash) in the host OS. (CVE-2015-8104)\n\n郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nDmitry Vyukov discovered that the Linux kernel's keyring handler attempted\nto garbage collect incompletely instantiated keys. A local unprivileged\nattacker could use this to cause a denial of service (system crash).\n(CVE-2015-7872)\n\nIt was discovered that the virtual video osd test driver in the Linux\nkernel did not properly initialize data structures. A local attacker could\nuse this to obtain sensitive information from the kernel. (CVE-2015-7884)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-wily","version":"4.2.0-21.25~14.04.1","description":"Linux hardware enablement kernel from Wily","is_source":true},{"name":"linux-image-4.2.0-21-generic","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"},{"name":"linux-image-4.2.0-21-generic-lpae","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"},{"name":"linux-image-4.2.0-21-lowlatency","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"},{"name":"linux-image-4.2.0-21-powerpc-e500mc","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"},{"name":"linux-image-4.2.0-21-powerpc-smp","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"},{"name":"linux-image-4.2.0-21-powerpc64-emb","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"},{"name":"linux-image-4.2.0-21-powerpc64-smp","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"},{"name":"linux-image-extra-4.2.0-21-generic","version":"4.2.0-21.25~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-wily/4.2.0-21.25~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7872","CVE-2015-7884","CVE-2015-7885","CVE-2015-8104"]},{"id":"USN-2842-2","title":"Linux kernel (Vivid HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T08:08:16.220107","description":"Jan Beulich discovered that the KVM svm hypervisor implementation in the\nLinux kernel did not properly catch Debug exceptions on AMD processors. An\nattacker in a guest virtual machine could use this to cause a denial of\nservice (system crash) in the host OS. (CVE-2015-8104)\n\n郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nIt was discovered that the virtual video osd test driver in the Linux\nkernel did not properly initialize data structures. A local attacker could\nuse this to obtain sensitive information from the kernel. (CVE-2015-7884)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-vivid","version":"3.19.0-41.46~14.04.2","description":"Linux hardware enablement kernel from Vivid","is_source":true},{"name":"linux-image-3.19.0-41-generic","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"},{"name":"linux-image-3.19.0-41-generic-lpae","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"},{"name":"linux-image-3.19.0-41-lowlatency","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"},{"name":"linux-image-3.19.0-41-powerpc-e500mc","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"},{"name":"linux-image-3.19.0-41-powerpc-smp","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"},{"name":"linux-image-3.19.0-41-powerpc64-emb","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"},{"name":"linux-image-3.19.0-41-powerpc64-smp","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"},{"name":"linux-image-extra-3.19.0-41-generic","version":"3.19.0-41.46~14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-vivid/3.19.0-41.46~14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7884","CVE-2015-7885","CVE-2015-8104"]},{"id":"USN-2844-1","title":"Linux kernel (Utopic HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T08:34:39.157413","description":"Jan Beulich discovered that the KVM svm hypervisor implementation in the\nLinux kernel did not properly catch Debug exceptions on AMD processors. An\nattacker in a guest virtual machine could use this to cause a denial of\nservice (system crash) in the host OS. (CVE-2015-8104)\n\n郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-utopic","version":"3.16.0-56.75~14.04.1","description":"Linux hardware enablement kernel from Utopic","is_source":true},{"name":"linux-image-3.16.0-56-generic","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-56-generic-lpae","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-56-lowlatency","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-56-powerpc-e500mc","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-56-powerpc-smp","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-56-powerpc64-emb","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-56-powerpc64-smp","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"},{"name":"linux-image-extra-3.16.0-56-generic","version":"3.16.0-56.75~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-56.75~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7885","CVE-2015-8104"]},{"id":"USN-2841-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T07:25:06.811745","description":"Jan Beulich discovered that the KVM svm hypervisor implementation in the\nLinux kernel did not properly catch Debug exceptions on AMD processors. An\nattacker in a guest virtual machine could use this to cause a denial of\nservice (system crash) in the host OS. (CVE-2015-8104)\n\n郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-73.116","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-73-generic","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-3.13.0-73-generic-lpae","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-3.13.0-73-lowlatency","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-3.13.0-73-powerpc-e500","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-3.13.0-73-powerpc-e500mc","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-3.13.0-73-powerpc-smp","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-3.13.0-73-powerpc64-emb","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-3.13.0-73-powerpc64-smp","version":"3.13.0-73.116","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"},{"name":"linux-image-extra-3.13.0-73-generic","version":"3.13.0-73.116","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-73.116","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7885","CVE-2015-8104"]},{"id":"USN-2841-2","title":"Linux kernel (Trusty HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T07:50:55.248312","description":"Jan Beulich discovered that the KVM svm hypervisor implementation in the\nLinux kernel did not properly catch Debug exceptions on AMD processors. An\nattacker in a guest virtual machine could use this to cause a denial of\nservice (system crash) in the host OS. (CVE-2015-8104)\n\n郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-73.116~precise1","description":"Linux hardware enablement kernel from Trusty","is_source":true},{"name":"linux-image-3.13.0-73-generic-lpae","version":"3.13.0-73.116~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-73.116~precise1"},{"name":"linux-image-3.13.0-73-generic","version":"3.13.0-73.116~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-73.116~precise1"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7885","CVE-2015-8104"]},{"id":"USN-2842-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T08:01:21.576694","description":"Jan Beulich discovered that the KVM svm hypervisor implementation in the\nLinux kernel did not properly catch Debug exceptions on AMD processors. An\nattacker in a guest virtual machine could use this to cause a denial of\nservice (system crash) in the host OS. (CVE-2015-8104)\n\n郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nIt was discovered that the virtual video osd test driver in the Linux\nkernel did not properly initialize data structures. A local attacker could\nuse this to obtain sensitive information from the kernel. (CVE-2015-7884)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"vivid":[{"name":"linux","version":"3.19.0-41.46","description":"Linux kernel","is_source":true},{"name":"linux-image-3.19.0-41-powerpc64-emb","version":"3.19.0-41.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.19.0-41.46"},{"name":"linux-image-3.19.0-41-generic","version":"3.19.0-41.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.19.0-41.46"},{"name":"linux-image-3.19.0-41-powerpc64-smp","version":"3.19.0-41.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.19.0-41.46"},{"name":"linux-image-3.19.0-41-powerpc-e500mc","version":"3.19.0-41.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.19.0-41.46"},{"name":"linux-image-3.19.0-41-lowlatency","version":"3.19.0-41.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.19.0-41.46"},{"name":"linux-image-3.19.0-41-powerpc-smp","version":"3.19.0-41.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.19.0-41.46"},{"name":"linux-image-3.19.0-41-generic-lpae","version":"3.19.0-41.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.19.0-41.46"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7884","CVE-2015-7885","CVE-2015-8104"]},{"id":"USN-2843-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T08:16:04.005526","description":"Jan Beulich discovered that the KVM svm hypervisor implementation in the\nLinux kernel did not properly catch Debug exceptions on AMD processors. An\nattacker in a guest virtual machine could use this to cause a denial of\nservice (system crash) in the host OS. (CVE-2015-8104)\n\n郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nDmitry Vyukov discovered that the Linux kernel's keyring handler attempted\nto garbage collect incompletely instantiated keys. A local unprivileged\nattacker could use this to cause a denial of service (system crash).\n(CVE-2015-7872)\n\nIt was discovered that the virtual video osd test driver in the Linux\nkernel did not properly initialize data structures. A local attacker could\nuse this to obtain sensitive information from the kernel. (CVE-2015-7884)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"wily":[{"name":"linux","version":"4.2.0-21.25","description":"Linux kernel","is_source":true},{"name":"linux-image-4.2.0-21-powerpc64-emb","version":"4.2.0-21.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.2.0-21.25"},{"name":"linux-image-4.2.0-21-powerpc-smp","version":"4.2.0-21.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.2.0-21.25"},{"name":"linux-image-4.2.0-21-lowlatency","version":"4.2.0-21.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.2.0-21.25"},{"name":"linux-image-4.2.0-21-generic-lpae","version":"4.2.0-21.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.2.0-21.25"},{"name":"linux-image-4.2.0-21-generic","version":"4.2.0-21.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.2.0-21.25"},{"name":"linux-image-4.2.0-21-powerpc-e500mc","version":"4.2.0-21.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.2.0-21.25"},{"name":"linux-image-4.2.0-21-powerpc64-smp","version":"4.2.0-21.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.2.0-21.25"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7872","CVE-2015-7884","CVE-2015-7885","CVE-2015-8104"]},{"id":"USN-2843-3","title":"Linux kernel (Raspberry Pi 2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-12-17T19:37:22.503903","description":"郭永刚 discovered that the ppp implementation in the Linux kernel did\nnot ensure that certain slot numbers are valid. A local attacker with the\nprivilege to call ioctl() on /dev/ppp could cause a denial of service\n(system crash). (CVE-2015-7799)\n\nDmitry Vyukov discovered that the Linux kernel's keyring handler attempted\nto garbage collect incompletely instantiated keys. A local unprivileged\nattacker could use this to cause a denial of service (system crash).\n(CVE-2015-7872)\n\nIt was discovered that the virtual video osd test driver in the Linux\nkernel did not properly initialize data structures. A local attacker could\nuse this to obtain sensitive information from the kernel. (CVE-2015-7884)\n\nIt was discovered that the driver for Digi Neo and ClassicBoard devices did\nnot properly initialize data structures. A local attacker could use this to\nobtain sensitive information from the kernel. (CVE-2015-7885)\n","is_hidden":false,"release_packages":{"wily":[{"name":"linux-raspi2","version":"4.2.0-1016.23","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-image-4.2.0-1016-raspi2","version":"4.2.0-1016.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.2.0-1016.23"}]},"type":"USN","cves_ids":["CVE-2015-7799","CVE-2015-7872","CVE-2015-7884","CVE-2015-7885"]}]}],"offset":62380,"limit":20,"total_results":79316}