{"cves":[{"id":"CVE-2014-9651","published":"2015-08-28T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and\nbefore 5.0 allows attackers to have unspecified impact via a positive START\nargument to the \"substring-index[-ci] procedures.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-9651"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775346"],"patches":{"chicken":[]},"tags":{},"packages":[{"name":"chicken","source":"https://ubuntu.com/security/cve?package=chicken","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chicken","debian":"https://tracker.debian.org/pkg/chicken","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.10.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6833","published":"2015-08-27T00:00:00","updated_at":"2025-08-25T21:44:24.047351+00:00","description":"\nDirectory traversal vulnerability in the PharData class in PHP before\n5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote\nattackers to write to arbitrary files via a .. (dot dot) in a ZIP archive\nentry that is mishandled during an extractTo call.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/19/3","http://seclists.org/oss-sec/2015/q3/523","https://ubuntu.com/security/notices/USN-2758-1","https://www.cve.org/CVERecord?id=CVE-2015-6833"],"bugs":["https://bugs.php.net/bug.php?id=70019"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=dda81f0505217a95db065e6bf9cc2d81eb902417","upstream: http://git.php.net/?p=php-src.git;a=commit;h=eb7ba73079b73ca4ef91307ae1ef30b43468717b"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.12+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"5.6.4+dfsg-4ubuntu6.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2758-1"],"notices":[{"id":"USN-2758-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-09-30T20:10:18.317849","description":"It was discovered that the PHP phar extension incorrectly handled certain\nfiles. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2015-5589)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\nfilepaths. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-5590)\n\nTaoguang Chen discovered that PHP incorrectly handled unserializing\nobjects. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6831, CVE-2015-6834, CVE-2015-6835\n\nSean Heelan discovered that PHP incorrectly handled unserializing\nobjects. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6832)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\narchives. A remote attacker could use this issue to cause files to be\nplaced outside of the destination directory. (CVE-2015-6833)\n\nAndrea Palazzo discovered that the PHP Soap client incorrectly validated\ndata types. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6836)\n\nIt was discovered that the PHP XSLTProcessor class incorrectly handled\ncertain data. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2015-6837)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.20","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.13","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"}],"vivid":[{"name":"php5","version":"5.6.4+dfsg-4ubuntu6.3","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-cgi","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-cli","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-fpm","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"}]},"type":"USN","cves_ids":["CVE-2015-5589","CVE-2015-5590","CVE-2015-6831","CVE-2015-6832","CVE-2015-6833","CVE-2015-6834","CVE-2015-6835","CVE-2015-6836","CVE-2015-6837","CVE-2015-6838"]}]},{"id":"CVE-2015-6832","published":"2015-08-27T00:00:00","updated_at":"2025-08-25T21:44:24.047351+00:00","description":"\nUse-after-free vulnerability in the SPL unserialize implementation in\next/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x\nbefore 5.6.12 allows remote attackers to execute arbitrary code via crafted\nserialized data that triggers misuse of an array field.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2015/q3/523","http://www.openwall.com/lists/oss-security/2015/08/19/3","https://ubuntu.com/security/notices/USN-2758-1","https://www.cve.org/CVERecord?id=CVE-2015-6832"],"bugs":["https://bugs.php.net/bug.php?id=70068"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=b7fa67742cd8d2b0ca0c0273b157f6ffee9ad6e2"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.12+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"5.6.4+dfsg-4ubuntu6.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2758-1"],"notices":[{"id":"USN-2758-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-09-30T20:10:18.317849","description":"It was discovered that the PHP phar extension incorrectly handled certain\nfiles. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2015-5589)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\nfilepaths. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-5590)\n\nTaoguang Chen discovered that PHP incorrectly handled unserializing\nobjects. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6831, CVE-2015-6834, CVE-2015-6835\n\nSean Heelan discovered that PHP incorrectly handled unserializing\nobjects. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6832)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\narchives. A remote attacker could use this issue to cause files to be\nplaced outside of the destination directory. (CVE-2015-6833)\n\nAndrea Palazzo discovered that the PHP Soap client incorrectly validated\ndata types. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6836)\n\nIt was discovered that the PHP XSLTProcessor class incorrectly handled\ncertain data. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2015-6837)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.20","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.13","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"}],"vivid":[{"name":"php5","version":"5.6.4+dfsg-4ubuntu6.3","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-cgi","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-cli","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-fpm","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"}]},"type":"USN","cves_ids":["CVE-2015-5589","CVE-2015-5590","CVE-2015-6831","CVE-2015-6832","CVE-2015-6833","CVE-2015-6834","CVE-2015-6835","CVE-2015-6836","CVE-2015-6837","CVE-2015-6838"]}]},{"id":"CVE-2015-6831","published":"2015-08-27T00:00:00","updated_at":"2025-08-25T21:44:24.047351+00:00","description":"\nMultiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x\nbefore 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute\narbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage,\nand (3) SplDoublyLinkedList, which are mishandled during unserialization.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/19/3","https://ubuntu.com/security/notices/USN-2758-1","https://www.cve.org/CVERecord?id=CVE-2015-6831"],"bugs":["https://bugs.php.net/bug.php?id=70155","https://bugs.php.net/bug.php?id=70166","https://bugs.php.net/bug.php?id=70168","https://bugs.php.net/bug.php?id=70169"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=7381b6accc5559b2de039af3a22f6ec1003b03b3","upstream: http://git.php.net/?p=php-src.git;a=commit;h=c2e197e4efc663ca55f393bf0e799848842286f3","upstream: http://git.php.net/?p=php-src.git;a=commit;h=863bf294feb9ad425eadb94f288bc7f18673089d"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.12+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"5.6.4+dfsg-4ubuntu6.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2758-1"],"notices":[{"id":"USN-2758-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-09-30T20:10:18.317849","description":"It was discovered that the PHP phar extension incorrectly handled certain\nfiles. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2015-5589)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\nfilepaths. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-5590)\n\nTaoguang Chen discovered that PHP incorrectly handled unserializing\nobjects. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6831, CVE-2015-6834, CVE-2015-6835\n\nSean Heelan discovered that PHP incorrectly handled unserializing\nobjects. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6832)\n\nIt was discovered that the PHP phar extension incorrectly handled certain\narchives. A remote attacker could use this issue to cause files to be\nplaced outside of the destination directory. (CVE-2015-6833)\n\nAndrea Palazzo discovered that the PHP Soap client incorrectly validated\ndata types. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-6836)\n\nIt was discovered that the PHP XSLTProcessor class incorrectly handled\ncertain data. A remote attacker could use this issue to cause PHP to crash,\nresulting in a denial of service. (CVE-2015-6837)\n","is_hidden":false,"release_packages":{"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.20","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.20"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.13","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.13","pocket":"security"}],"vivid":[{"name":"php5","version":"5.6.4+dfsg-4ubuntu6.3","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-cgi","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-cli","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"},{"name":"php5-fpm","version":"5.6.4+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.3"}]},"type":"USN","cves_ids":["CVE-2015-5589","CVE-2015-5590","CVE-2015-6831","CVE-2015-6832","CVE-2015-6833","CVE-2015-6834","CVE-2015-6835","CVE-2015-6836","CVE-2015-6837","CVE-2015-6838"]}]},{"id":"CVE-2015-4498","published":"2015-08-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe add-on installation feature in Mozilla Firefox before 40.0.3 and\nFirefox ESR 38.x before 38.2.1 allows remote attackers to bypass an\nintended user-confirmation requirement by constructing a crafted data: URL\nand triggering navigation to an arbitrary http: or https: URL at a certain\nearly point in the installation process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-95/","https://ubuntu.com/security/notices/USN-2723-1","https://www.cve.org/CVERecord?id=CVE-2015-4498"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"released","description":"40.0.3+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"40.0.3+build1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"40.0.3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"40.0.3+build1-0ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2723-1"],"notices":[{"id":"USN-2723-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":[],"published":"2015-08-27T18:21:35.355609","description":"A use-after-free was discovered when resizing a canvas element during\nrestyling in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via application crash, or execute arbitrary code\nwith the privileges of the user invoking Firefox. (CVE-2015-4497)\n\nBas Venis discovered that the addon install permission prompt could be\nbypassed using data: URLs in some circumstances. It was also discovered\nthat the installation notification could be made to appear over another\nsite. If a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to install a malicious addon.\n(CVE-2015-4498)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"40.0.3+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"40.0.3+build1-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.12.04.1"}],"trusty":[{"name":"firefox","version":"40.0.3+build1-0ubuntu0.14.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-dev","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-globalmenu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-af","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-an","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ar","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-as","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ast","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-az","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-be","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bg","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-br","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bs","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ca","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cs","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-csb","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cy","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-da","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-de","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-el","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-en","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eo","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-es","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-et","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fa","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fi","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fy","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ga","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gd","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-he","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hi","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hsb","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hy","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-id","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-is","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-it","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ja","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ka","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-km","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ko","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ku","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lg","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lt","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lv","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mai","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ml","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ms","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nb","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nso","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-oc","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-or","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pa","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pt","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ro","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ru","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-si","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sq","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sv","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sw","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ta","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-te","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-th","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-tr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uz","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-vi","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-xh","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hans","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hant","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-mozsymbols","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-testsuite","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"}],"vivid":[{"name":"firefox","version":"40.0.3+build1-0ubuntu0.15.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"40.0.3+build1-0ubuntu0.15.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.15.04.1"}]},"type":"USN","cves_ids":["CVE-2015-4497","CVE-2015-4498"]}]},{"id":"CVE-2015-4497","published":"2015-08-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the CanvasRenderingContext2D implementation\nin Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows\nremote attackers to execute arbitrary code by leveraging improper\ninteraction between resize events and changes to Cascading Style Sheets\n(CSS) token sequences for a CANVAS element.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/en-US/security/advisories/mfsa2015-94/","https://ubuntu.com/security/notices/USN-2723-1","https://www.cve.org/CVERecord?id=CVE-2015-4497"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"precise","status":"released","description":"40.0.3+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"40.0.3+build1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"40.0.3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"40.0.3+build1-0ubuntu0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2723-1"],"notices":[{"id":"USN-2723-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":[],"published":"2015-08-27T18:21:35.355609","description":"A use-after-free was discovered when resizing a canvas element during\nrestyling in some circumstances. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit this to\ncause a denial of service via application crash, or execute arbitrary code\nwith the privileges of the user invoking Firefox. (CVE-2015-4497)\n\nBas Venis discovered that the addon install permission prompt could be\nbypassed using data: URLs in some circumstances. It was also discovered\nthat the installation notification could be made to appear over another\nsite. If a user were tricked in to opening a specially crafted website, an\nattacker could potentially exploit this to install a malicious addon.\n(CVE-2015-4498)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"40.0.3+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"40.0.3+build1-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.12.04.1"}],"trusty":[{"name":"firefox","version":"40.0.3+build1-0ubuntu0.14.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-dev","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-globalmenu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-af","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-an","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ar","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-as","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ast","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-az","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-be","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bg","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-br","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-bs","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ca","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cs","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-csb","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-cy","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-da","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-de","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-el","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-en","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eo","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-es","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-et","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-eu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fa","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fi","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-fy","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ga","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gd","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-gu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-he","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hi","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hsb","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-hy","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-id","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-is","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-it","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ja","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ka","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-km","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-kn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ko","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ku","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lg","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lt","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-lv","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mai","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ml","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-mr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ms","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nb","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nn","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-nso","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-oc","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-or","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pa","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-pt","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ro","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ru","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-si","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sl","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sq","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sv","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-sw","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-ta","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-te","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-th","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-tr","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uk","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-uz","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-vi","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-xh","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hans","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zh-hant","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-locale-zu","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-mozsymbols","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"},{"name":"firefox-testsuite","version":"40.0.3+build1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.14.04.1","pocket":"security"}],"vivid":[{"name":"firefox","version":"40.0.3+build1-0ubuntu0.15.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"40.0.3+build1-0ubuntu0.15.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/40.0.3+build1-0ubuntu0.15.04.1"}]},"type":"USN","cves_ids":["CVE-2015-4497","CVE-2015-4498"]}]},{"id":"CVE-2015-3239","published":"2015-08-26T19:59:00","updated_at":"2024-12-05T13:31:53.758578+00:00","description":"\nOff-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h\nin libunwind 1.1 allows local users to have unspecified impact via invalid\ndwarf opcodes.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"I saw nothing in callers of this macro that would prevent\nless-than-zero accesses: input params were sometimes integers, sometimes\nharder to determine the type. Debian codesearch shows many duplications of\nthe <= mistake with dwarf_to_unw_regnum arrays in other files, not just the\none dwarf_i.h."},{"author":"mdeslaur","note":"We do not support security updates for Android components,\nmarking as ignored."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://savannah.nongnu.org/bugs/?45276","http://git.savannah.gnu.org/cgit/libunwind.git/commit/?id=396b6c7ab737e2bff244d640601c436a26260ca1","https://www.cve.org/CVERecord?id=CVE-2015-3239"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=790830"],"patches":{"libunwind":["upstream: http://git.savannah.gnu.org/cgit/libunwind.git/commit/?id=396b6c7ab737e2bff244d640601c436a26260ca1"],"racket":["other: http://git.savannah.gnu.org/cgit/libunwind.git/commit/?id=396b6c7ab737e2bff244d640601c436a26260ca1"],"android-platform-external-libunwind":["upstream: http://git.savannah.gnu.org/cgit/libunwind.git/commit/?id=396b6c7ab737e2bff244d640601c436a26260ca1"]},"tags":{},"packages":[{"name":"racket","source":"https://ubuntu.com/security/cve?package=racket","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=racket","debian":"https://tracker.debian.org/pkg/racket","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]},{"name":"android-platform-external-libunwind","source":"https://ubuntu.com/security/cve?package=android-platform-external-libunwind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android-platform-external-libunwind","debian":"https://tracker.debian.org/pkg/android-platform-external-libunwind","statuses":[{"release_codename":"bionic","status":"not-affected","description":"7.0.0+r1-4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0+r1-4","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"8.1.0+r23-2","component":null,"pocket":"security"}]},{"name":"libunwind","source":"https://ubuntu.com/security/cve?package=libunwind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libunwind","debian":"https://tracker.debian.org/pkg/libunwind","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.99-0.2+deb6u1, 1.1-4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.1-4.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3221","published":"2015-08-26T19:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1\n(kilo), when using the IPTables firewall driver, allows remote\nauthenticated users to cause a denial of service (L2 agent crash) by adding\nan address pair that is rejected by the ipset tool.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"DoS possible by an authenticated user"},{"author":"mdeslaur","note":"ipset code introduced in juno"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/06/23/3","https://www.cve.org/CVERecord?id=CVE-2015-3221"],"bugs":["https://bugs.launchpad.net/neutron/+bug/1461054/comments/18","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=789713"],"patches":{"neutron":["upstream: https://review.openstack.org/194696","upstream: https://review.openstack.org/194697","upstream: https://review.openstack.org/194695"]},"tags":{},"packages":[{"name":"neutron","source":"https://ubuntu.com/security/cve?package=neutron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neutron","debian":"https://tracker.debian.org/pkg/neutron","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2015.1.0+2015.06.24.git61.bdf194a0e1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:2015.1.1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [code not present]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-7424","published":"2015-08-26T19:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe getaddrinfo function in glibc before 2.15, when compiled with libidn\nand the AI_IDN flag is used, allows context-dependent attackers to cause a\ndenial of service (invalid free) and possibly execute arbitrary code via\nunspecified vectors, as demonstrated by an internationalized domain name to\nping6.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced by https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commit;h=34a9094f49241ebb72084c536cf468fd51ebe3ec\nlucid doesn't look vulnerable"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-7424"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=981942"],"patches":{"eglibc":[],"glibc":["upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commit;h=2e96f1c7"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.15-0ubuntu10.10","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.19-0ubuntu6.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"2.19-10ubuntu2.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5949","published":"2015-08-25T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nVideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial\nof service (crash) and possibly execute arbitrary code via a crafted 3GP\nfile, which triggers the freeing of arbitrary pointers.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code in trusty and earlier is different, and reproducer doesn't\nwork."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.ocert.org/advisories/ocert-2015-009.html","https://www.cve.org/CVERecord?id=CVE-2015-5949"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796255","https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1487601"],"patches":{"vlc":["upstream: https://git.videolan.org/?p=vlc/vlc-2.2.git;a=commit;h=ce91452460a75d7424b165c4dc8db98114c3cbd9"]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"precise","status":"not-affected","description":"2.0.8-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.1-3","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.2.1-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.2.2-5","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected [2.1.6-0ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5161","published":"2015-08-25T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework\nbefore 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running\nunder PHP-FPM in a threaded environment, allows remote attackers to bypass\nsecurity checks and conduct XML external entity (XXE) and XML entity\nexpansion (XEE) attacks via multibyte encoded characters.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Doesn't affect php-zend-xml when used with PHP 5.5 >= 5.5.22,\nPHP 5.6 >= 5.6.6, and PHP 7"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://framework.zend.com/security/advisory/ZF2015-06","https://www.cve.org/CVERecord?id=CVE-2015-5161"],"bugs":[""],"patches":{"php-zend-xml":[]},"tags":{},"packages":[{"name":"php-zend-xml","source":"https://ubuntu.com/security/cve?package=php-zend-xml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-zend-xml","debian":"https://tracker.debian.org/pkg/php-zend-xml","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4020","published":"2015-08-25T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8\ndoes not validate the hostname when fetching gems or making API requests,\nwhich allows remote attackers to redirect requests to arbitrary domains via\na crafted DNS SRV record with a domain that is suffixed with the original\ndomain name, aka a \"DNS hijack attack.\" NOTE: this vulnerability exists\nbecause to an incomplete fix for CVE-2015-3900.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"rubygems is for users of ruby1.8. ruby1.9.1 and jruby ship an\nembedded rubygems."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/rubygems/rubygems/commit/5c7bfb5","https://www.cve.org/CVERecord?id=CVE-2015-4020"],"bugs":[""],"patches":{"rubygems":[],"ruby1.9.1":[],"jruby":[],"libgems-ruby":[],"ruby1.8":[],"ruby2.2":[],"ruby2.1":[]},"tags":{},"packages":[{"name":"jruby","source":"https://ubuntu.com/security/cve?package=jruby","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jruby","debian":"https://tracker.debian.org/pkg/jruby","statuses":[{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"libgems-ruby","source":"https://ubuntu.com/security/cve?package=libgems-ruby","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgems-ruby","debian":"https://tracker.debian.org/pkg/libgems-ruby","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]},{"name":"ruby2.1","source":"https://ubuntu.com/security/cve?package=ruby2.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.1","debian":"https://tracker.debian.org/pkg/ruby2.1","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"ruby2.2","source":"https://ubuntu.com/security/cve?package=ruby2.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.2","debian":"https://tracker.debian.org/pkg/ruby2.2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"rubygems","source":"https://ubuntu.com/security/cve?package=rubygems","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rubygems","debian":"https://tracker.debian.org/pkg/rubygems","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-2150","published":"2015-08-25T17:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nxfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file\ndata, which allows remote attackers to obtain sensitive information by\nreading a generated image.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Fixed upstream in 3.2.4"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://oss.sgi.com/pipermail/xfs/2015-July/042726.html","https://www.cve.org/CVERecord?id=CVE-2012-2150"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=817696"],"patches":{"xfsprogs":[]},"tags":{},"packages":[{"name":"xfsprogs","source":"https://ubuntu.com/security/cve?package=xfsprogs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xfsprogs","debian":"https://tracker.debian.org/pkg/xfsprogs","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.3.0+nmu1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5225","published":"2015-08-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the vnc_refresh_server_surface function in the VNC\ndisplay driver in QEMU before 2.4.0.1 allows guest users to cause a denial\nof service (heap memory corruption and process crash) or possibly execute\narbitrary code on the host via unspecified vectors, related to refreshing\nthe server display surface.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced by:\nhttp://git.qemu.org/?p=qemu.git;a=commit;h=bea60dd7679364493a0d7f5b\nso precise and trusty are not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2724-1","https://www.cve.org/CVERecord?id=CVE-2015-5225"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1255896","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796465"],"patches":{"qemu-kvm":[],"qemu":["other: https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.html"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:2.2+dfsg-5expubuntu9.4","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2724-1"],"notices":[{"id":"USN-2724-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2015-08-27T12:00:41.799297","description":"It was discovered that QEMU incorrectly handled a PRDT with zero complete\nsectors in the IDE functionality. A malicious guest could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-9718)\n\nDonghai Zhu discovered that QEMU incorrectly handled the RTL8139 driver.\nA malicious guest could possibly use this issue to read sensitive\ninformation from arbitrary host memory. (CVE-2015-5165)\n\nDonghai Zhu discovered that QEMU incorrectly handled unplugging emulated\nblock devices. A malicious guest could use this issue to cause a denial of\nservice, or possibly execute arbitrary code on the host as the user running\nthe QEMU process. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile. This\nissue only affected Ubuntu 15.04. (CVE-2015-5166)\n\nQinghao Tang and Mr. Zuozhi discovered that QEMU incorrectly handled memory\nin the VNC display driver. A malicious guest could use this issue to cause\na denial of service, or possibly execute arbitrary code on the host as the\nuser running the QEMU process. In the default installation, when QEMU is\nused with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. This issue only affected Ubuntu 15.04. (CVE-2015-5225)\n\nIt was discovered that QEMU incorrectly handled the virtio-serial device.\nA malicious guest could use this issue to cause a denial of service, or\npossibly execute arbitrary code on the host as the user running the QEMU\nprocess. In the default installation, when QEMU is used with libvirt,\nattackers would be isolated by the libvirt AppArmor profile. This issue\nonly affected Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-5745)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.24","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.24"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.17","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.17","pocket":"security"}],"vivid":[{"name":"qemu","version":"1:2.2+dfsg-5expubuntu9.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"},{"name":"qemu-system-aarch64","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"},{"name":"qemu-system-arm","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"},{"name":"qemu-system-mips","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"},{"name":"qemu-system-misc","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"},{"name":"qemu-system-ppc","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"},{"name":"qemu-system-sparc","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"},{"name":"qemu-system-x86","version":"1:2.2+dfsg-5expubuntu9.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.4"}]},"type":"USN","cves_ids":["CVE-2014-9718","CVE-2015-5165","CVE-2015-5166","CVE-2015-5225","CVE-2015-5745"]}]},{"id":"CVE-2015-5219","published":"2015-08-25T00:00:00","updated_at":"2025-08-25T21:41:14.824585+00:00","description":"\nThe ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly\nperform type conversions from a precision value to a double, which allows\nremote attackers to cause a denial of service (infinite loop) via a crafted\nNTP packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/25/3","https://ubuntu.com/security/notices/USN-2783-1","https://www.cve.org/CVERecord?id=CVE-2015-5219"],"bugs":["http://bugs.ntp.org/show_bug.cgi?id=2382"],"patches":{"ntp":["upstream: https://github.com/ntp-project/ntp/commit/5f295cd05c3c136d39f5b3e500a2d781bdbb59c8"]},"tags":{},"packages":[{"name":"ntp","source":"https://ubuntu.com/security/cve?package=ntp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntp","debian":"https://tracker.debian.org/pkg/ntp","statuses":[{"release_codename":"vivid","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:4.2.6.p3+dfsg-1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu8.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2783-1"],"notices":[{"id":"USN-2783-1","title":"NTP vulnerabilities","summary":"Several security issues were fixed in NTP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-10-27T17:02:35.840612","description":"Aleksis Kauppinen discovered that NTP incorrectly handled certain remote\nconfig packets. In a non-default configuration, a remote authenticated\nattacker could possibly use this issue to cause NTP to crash, resulting in\na denial of service. (CVE-2015-5146)\n\nMiroslav Lichvar discovered that NTP incorrectly handled logconfig\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5194)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain statistics\ntypes. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5195)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain file\npaths. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service, or overwrite certain files. (CVE-2015-5196, CVE-2015-7703)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain packets.\nA remote attacker could possibly use this issue to cause NTP to hang,\nresulting in a denial of service. (CVE-2015-5219)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled restarting after hitting a panic threshold. A remote\nattacker could possibly use this issue to alter the system time on clients.\n(CVE-2015-5300)\n\nIt was discovered that NTP incorrectly handled autokey data packets. A\nremote attacker could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7691, CVE-2015-7692, CVE-2015-7702)\n\nIt was discovered that NTP incorrectly handled memory when processing\ncertain autokey messages. A remote attacker could possibly use this issue\nto cause NTP to consume memory, resulting in a denial of service.\n(CVE-2015-7701)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled rate limiting. A remote attacker could possibly use\nthis issue to cause clients to stop updating their clock. (CVE-2015-7704,\nCVE-2015-7705)\n\nYves Younan discovered that NTP incorrectly handled logfile and keyfile\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to enter a loop, resulting in a\ndenial of service. (CVE-2015-7850)\n\nYves Younan and Aleksander Nikolich discovered that NTP incorrectly handled\nascii conversion. A remote attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2015-7852)\n\nYves Younan discovered that NTP incorrectly handled reference clock memory.\nA malicious refclock could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7853)\n\nJohn D \"Doug\" Birdwell discovered that NTP incorrectly handled decoding\ncertain bogus values. An attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service. (CVE-2015-7855)\n\nStephen Gray discovered that NTP incorrectly handled symmetric association\nauthentication. A remote attacker could use this issue to possibly bypass\nauthentication and alter the system clock. (CVE-2015-7871)\n\nIn the default installation, attackers would be isolated by the NTP\nAppArmor profile.\n","is_hidden":false,"release_packages":{"precise":[{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p3+dfsg-1ubuntu3.6"}],"trusty":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntp-doc","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntpdate","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"}],"vivid":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu6.2"}],"wily":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2015-5146","CVE-2015-5194","CVE-2015-5195","CVE-2015-5196","CVE-2015-5219","CVE-2015-5300","CVE-2015-7691","CVE-2015-7692","CVE-2015-7701","CVE-2015-7702","CVE-2015-7703","CVE-2015-7704","CVE-2015-7705","CVE-2015-7850","CVE-2015-7852","CVE-2015-7853","CVE-2015-7855","CVE-2015-7871"]}]},{"id":"CVE-2015-5196","published":"2015-08-25T00:00:00","updated_at":"2025-08-04T19:24:32.789323+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2015-7703. Reason: This candidate is a reservation duplicate of\nCVE-2015-7703. Notes: All CVE users should reference CVE-2015-7703 instead\nof this candidate. All references and descriptions in this candidate have\nbeen removed to prevent accidental usage.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"dupe of CVE-2015-7703, this CVE was rejected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/25/3","https://ubuntu.com/security/notices/USN-2783-1","https://www.cve.org/CVERecord?id=CVE-2015-5196"],"bugs":[""],"patches":{"ntp":["upstream: https://github.com/ntp-project/ntp/commit/5dea6ff160c7e8f7cb038619ccccd28c3a8df637","vendor: http://pkgs.fedoraproject.org/cgit/ntp.git/tree/ntp-4.2.6p5-cve-2015-5196.patch"]},"tags":{},"packages":[{"name":"ntp","source":"https://ubuntu.com/security/cve?package=ntp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntp","debian":"https://tracker.debian.org/pkg/ntp","statuses":[{"release_codename":"precise","status":"released","description":"1:4.2.6.p3+dfsg-1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu8.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2783-1"],"notices":[{"id":"USN-2783-1","title":"NTP vulnerabilities","summary":"Several security issues were fixed in NTP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-10-27T17:02:35.840612","description":"Aleksis Kauppinen discovered that NTP incorrectly handled certain remote\nconfig packets. In a non-default configuration, a remote authenticated\nattacker could possibly use this issue to cause NTP to crash, resulting in\na denial of service. (CVE-2015-5146)\n\nMiroslav Lichvar discovered that NTP incorrectly handled logconfig\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5194)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain statistics\ntypes. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5195)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain file\npaths. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service, or overwrite certain files. (CVE-2015-5196, CVE-2015-7703)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain packets.\nA remote attacker could possibly use this issue to cause NTP to hang,\nresulting in a denial of service. (CVE-2015-5219)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled restarting after hitting a panic threshold. A remote\nattacker could possibly use this issue to alter the system time on clients.\n(CVE-2015-5300)\n\nIt was discovered that NTP incorrectly handled autokey data packets. A\nremote attacker could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7691, CVE-2015-7692, CVE-2015-7702)\n\nIt was discovered that NTP incorrectly handled memory when processing\ncertain autokey messages. A remote attacker could possibly use this issue\nto cause NTP to consume memory, resulting in a denial of service.\n(CVE-2015-7701)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled rate limiting. A remote attacker could possibly use\nthis issue to cause clients to stop updating their clock. (CVE-2015-7704,\nCVE-2015-7705)\n\nYves Younan discovered that NTP incorrectly handled logfile and keyfile\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to enter a loop, resulting in a\ndenial of service. (CVE-2015-7850)\n\nYves Younan and Aleksander Nikolich discovered that NTP incorrectly handled\nascii conversion. A remote attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2015-7852)\n\nYves Younan discovered that NTP incorrectly handled reference clock memory.\nA malicious refclock could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7853)\n\nJohn D \"Doug\" Birdwell discovered that NTP incorrectly handled decoding\ncertain bogus values. An attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service. (CVE-2015-7855)\n\nStephen Gray discovered that NTP incorrectly handled symmetric association\nauthentication. A remote attacker could use this issue to possibly bypass\nauthentication and alter the system clock. (CVE-2015-7871)\n\nIn the default installation, attackers would be isolated by the NTP\nAppArmor profile.\n","is_hidden":false,"release_packages":{"precise":[{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p3+dfsg-1ubuntu3.6"}],"trusty":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntp-doc","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntpdate","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"}],"vivid":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu6.2"}],"wily":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2015-5146","CVE-2015-5194","CVE-2015-5195","CVE-2015-5196","CVE-2015-5219","CVE-2015-5300","CVE-2015-7691","CVE-2015-7692","CVE-2015-7701","CVE-2015-7702","CVE-2015-7703","CVE-2015-7704","CVE-2015-7705","CVE-2015-7850","CVE-2015-7852","CVE-2015-7853","CVE-2015-7855","CVE-2015-7871"]}]},{"id":"CVE-2015-5195","published":"2015-08-25T00:00:00","updated_at":"2025-08-25T21:41:06.206693+00:00","description":"\nntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to\ncause a denial of service (segmentation fault) via a crafted statistics or\nfilegen configuration command that is not enabled during compilation.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/25/3","https://ubuntu.com/security/notices/USN-2783-1","https://www.cve.org/CVERecord?id=CVE-2015-5195"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1254544","http://bugs.ntp.org/show_bug.cgi?id=1773","http://bugs.ntp.org/show_bug.cgi?id=1774"],"patches":{"ntp":["upstream: https://github.com/ntp-project/ntp/commit/52e977d79a0c4ace997e5c74af429844da2f27be"]},"tags":{},"packages":[{"name":"ntp","source":"https://ubuntu.com/security/cve?package=ntp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntp","debian":"https://tracker.debian.org/pkg/ntp","statuses":[{"release_codename":"precise","status":"released","description":"1:4.2.6.p3+dfsg-1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu8.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2783-1"],"notices":[{"id":"USN-2783-1","title":"NTP vulnerabilities","summary":"Several security issues were fixed in NTP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-10-27T17:02:35.840612","description":"Aleksis Kauppinen discovered that NTP incorrectly handled certain remote\nconfig packets. In a non-default configuration, a remote authenticated\nattacker could possibly use this issue to cause NTP to crash, resulting in\na denial of service. (CVE-2015-5146)\n\nMiroslav Lichvar discovered that NTP incorrectly handled logconfig\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5194)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain statistics\ntypes. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5195)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain file\npaths. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service, or overwrite certain files. (CVE-2015-5196, CVE-2015-7703)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain packets.\nA remote attacker could possibly use this issue to cause NTP to hang,\nresulting in a denial of service. (CVE-2015-5219)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled restarting after hitting a panic threshold. A remote\nattacker could possibly use this issue to alter the system time on clients.\n(CVE-2015-5300)\n\nIt was discovered that NTP incorrectly handled autokey data packets. A\nremote attacker could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7691, CVE-2015-7692, CVE-2015-7702)\n\nIt was discovered that NTP incorrectly handled memory when processing\ncertain autokey messages. A remote attacker could possibly use this issue\nto cause NTP to consume memory, resulting in a denial of service.\n(CVE-2015-7701)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled rate limiting. A remote attacker could possibly use\nthis issue to cause clients to stop updating their clock. (CVE-2015-7704,\nCVE-2015-7705)\n\nYves Younan discovered that NTP incorrectly handled logfile and keyfile\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to enter a loop, resulting in a\ndenial of service. (CVE-2015-7850)\n\nYves Younan and Aleksander Nikolich discovered that NTP incorrectly handled\nascii conversion. A remote attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2015-7852)\n\nYves Younan discovered that NTP incorrectly handled reference clock memory.\nA malicious refclock could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7853)\n\nJohn D \"Doug\" Birdwell discovered that NTP incorrectly handled decoding\ncertain bogus values. An attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service. (CVE-2015-7855)\n\nStephen Gray discovered that NTP incorrectly handled symmetric association\nauthentication. A remote attacker could use this issue to possibly bypass\nauthentication and alter the system clock. (CVE-2015-7871)\n\nIn the default installation, attackers would be isolated by the NTP\nAppArmor profile.\n","is_hidden":false,"release_packages":{"precise":[{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p3+dfsg-1ubuntu3.6"}],"trusty":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntp-doc","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntpdate","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"}],"vivid":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu6.2"}],"wily":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2015-5146","CVE-2015-5194","CVE-2015-5195","CVE-2015-5196","CVE-2015-5219","CVE-2015-5300","CVE-2015-7691","CVE-2015-7692","CVE-2015-7701","CVE-2015-7702","CVE-2015-7703","CVE-2015-7704","CVE-2015-7705","CVE-2015-7850","CVE-2015-7852","CVE-2015-7853","CVE-2015-7855","CVE-2015-7871"]}]},{"id":"CVE-2015-5194","published":"2015-08-25T00:00:00","updated_at":"2025-08-25T21:41:06.206693+00:00","description":"\nThe log_config_command function in ntp_parser.y in ntpd in NTP before\n4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash)\nvia crafted logconfig commands.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/25/3","https://ubuntu.com/security/notices/USN-2783-1","https://www.cve.org/CVERecord?id=CVE-2015-5194"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1254542","http://bugs.ntp.org/show_bug.cgi?id=1593"],"patches":{"ntp":["upstream: https://github.com/ntp-project/ntp/commit/553f2fa65865c31c5e3c48812cfd46176cffdd27"]},"tags":{},"packages":[{"name":"ntp","source":"https://ubuntu.com/security/cve?package=ntp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntp","debian":"https://tracker.debian.org/pkg/ntp","statuses":[{"release_codename":"upstream","status":"released","description":"4.2.7p42","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:4.2.6.p3+dfsg-1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1:4.2.6.p5+dfsg-3ubuntu8.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2783-1"],"notices":[{"id":"USN-2783-1","title":"NTP vulnerabilities","summary":"Several security issues were fixed in NTP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-10-27T17:02:35.840612","description":"Aleksis Kauppinen discovered that NTP incorrectly handled certain remote\nconfig packets. In a non-default configuration, a remote authenticated\nattacker could possibly use this issue to cause NTP to crash, resulting in\na denial of service. (CVE-2015-5146)\n\nMiroslav Lichvar discovered that NTP incorrectly handled logconfig\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5194)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain statistics\ntypes. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service. (CVE-2015-5195)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain file\npaths. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to crash, resulting in a denial\nof service, or overwrite certain files. (CVE-2015-5196, CVE-2015-7703)\n\nMiroslav Lichvar discovered that NTP incorrectly handled certain packets.\nA remote attacker could possibly use this issue to cause NTP to hang,\nresulting in a denial of service. (CVE-2015-5219)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled restarting after hitting a panic threshold. A remote\nattacker could possibly use this issue to alter the system time on clients.\n(CVE-2015-5300)\n\nIt was discovered that NTP incorrectly handled autokey data packets. A\nremote attacker could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7691, CVE-2015-7692, CVE-2015-7702)\n\nIt was discovered that NTP incorrectly handled memory when processing\ncertain autokey messages. A remote attacker could possibly use this issue\nto cause NTP to consume memory, resulting in a denial of service.\n(CVE-2015-7701)\n\nAanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP\nincorrectly handled rate limiting. A remote attacker could possibly use\nthis issue to cause clients to stop updating their clock. (CVE-2015-7704,\nCVE-2015-7705)\n\nYves Younan discovered that NTP incorrectly handled logfile and keyfile\ndirectives. In a non-default configuration, a remote authenticated attacker\ncould possibly use this issue to cause NTP to enter a loop, resulting in a\ndenial of service. (CVE-2015-7850)\n\nYves Younan and Aleksander Nikolich discovered that NTP incorrectly handled\nascii conversion. A remote attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2015-7852)\n\nYves Younan discovered that NTP incorrectly handled reference clock memory.\nA malicious refclock could possibly use this issue to cause NTP to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2015-7853)\n\nJohn D \"Doug\" Birdwell discovered that NTP incorrectly handled decoding\ncertain bogus values. An attacker could possibly use this issue to cause\nNTP to crash, resulting in a denial of service. (CVE-2015-7855)\n\nStephen Gray discovered that NTP incorrectly handled symmetric association\nauthentication. A remote attacker could use this issue to possibly bypass\nauthentication and alter the system clock. (CVE-2015-7871)\n\nIn the default installation, attackers would be isolated by the NTP\nAppArmor profile.\n","is_hidden":false,"release_packages":{"precise":[{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p3+dfsg-1ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p3+dfsg-1ubuntu3.6"}],"trusty":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntp-doc","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"},{"name":"ntpdate","version":"1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5","pocket":"security"}],"vivid":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu6.2"}],"wily":[{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","description":"Network Time Protocol daemon and utility programs","is_source":true},{"name":"ntp","version":"1:4.2.6.p5+dfsg-3ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntp","version_link":"https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu8.1"}]},"type":"USN","cves_ids":["CVE-2015-5146","CVE-2015-5194","CVE-2015-5195","CVE-2015-5196","CVE-2015-5219","CVE-2015-5300","CVE-2015-7691","CVE-2015-7692","CVE-2015-7701","CVE-2015-7702","CVE-2015-7703","CVE-2015-7704","CVE-2015-7705","CVE-2015-7850","CVE-2015-7852","CVE-2015-7853","CVE-2015-7855","CVE-2015-7871"]}]},{"id":"CVE-2015-6249","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_wccp2r1_address_table_info function in\nepan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x\nbefore 1.12.7 does not prevent the conflicting use of a table for both IPv4\nand IPv6 addresses, which allows remote attackers to cause a denial of\nservice (application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=b1eaf29d4056f05d1bd6a7f3d692553ec069a228","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11358","http://www.wireshark.org/security/wnpa-sec-2015-29.html","https://www.cve.org/CVERecord?id=CVE-2015-6249"],"bugs":[""],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=b1eaf29d4056f05d1bd6a7f3d692553ec069a228"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6248","published":"2015-08-24T23:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ptvcursor_add function in the ptvcursor implementation in epan/proto.c\nin Wireshark 1.12.x before 1.12.7 does not check whether the expected\namount of data is available, which allows remote attackers to cause a\ndenial of service (application crash) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=5b53445e815fd6b652d49df03ec3d60b088c4fbc","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=3fc4a831e035604b0af14ed8a5c9f6596a3448d0","https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11358","http://www.wireshark.org/security/wnpa-sec-2015-28.html","https://www.cve.org/CVERecord?id=CVE-2015-6248"],"bugs":[""],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=5b53445e815fd6b652d49df03ec3d60b088c4fbc","upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=3fc4a831e035604b0af14ed8a5c9f6596a3448d0"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u3build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":62800,"limit":20,"total_results":79316}