{"cves":[{"id":"CVE-2015-0839","published":"2015-06-01T00:00:00","updated_at":"2025-08-25T21:33:02.590625+00:00","description":"\nThe hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it\neasier for man-in-the-middle attackers to execute arbitrary code by\nleveraging use of a short GPG key id from a keyserver to verify print\nplugin downloads.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"could either switch to using long key id 0x73D770CDA59047B9,\nor simply ship key in package."}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=143290483527532&w=2","https://ubuntu.com/security/notices/USN-2699-1","https://www.cve.org/CVERecord?id=CVE-2015-0839"],"bugs":["https://bugs.launchpad.net/bugs/1432516 (private)"],"patches":{"hplip":[]},"tags":{},"packages":[{"name":"hplip","source":"https://ubuntu.com/security/cve?package=hplip","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hplip","debian":"https://tracker.debian.org/pkg/hplip","statuses":[{"release_codename":"precise","status":"released","description":"3.12.2-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.14.3-0ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15.7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"3.15.2-0ubuntu4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2699-1"],"notices":[{"id":"USN-2699-1","title":"HPLIP vulnerability","summary":"HPLIP could be tricked into downloading a different GPG key when\nperforming printer plugin installations.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-07-30T16:56:09.314741","description":"Enrico Zini discovered that HPLIP used a short GPG key ID when downloading\nkeys from the keyserver. An attacker could possibly use this to return a\ndifferent key with a duplicate short key id and perform a machine-in-the-middle\nattack on printer plugin installations.\n","is_hidden":false,"release_packages":{"precise":[{"name":"hplip","version":"3.12.2-1ubuntu3.5","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hplip-data","version":"3.12.2-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.12.2-1ubuntu3.5"}],"trusty":[{"name":"hplip","version":"3.14.3-0ubuntu3.4","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"hplip","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"hplip-data","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"hplip-doc","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"hplip-gui","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"libhpmud-dev","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"libhpmud0","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"libsane-hpaio","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.14.3-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.14.3-0ubuntu3.4","pocket":"security"}],"vivid":[{"name":"hplip","version":"3.15.2-0ubuntu4.2","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hplip-data","version":"3.15.2-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.15.2-0ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2015-0839"]}]},{"id":"CVE-2015-1833","published":"2015-05-29T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6,\n2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before\n2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary\nfiles and send requests to intranet servers via a crafted WebDAV request.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"package only contains webdav module; however, vuln affects\nwebdav module"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://issues.apache.org/jira/browse/JCR-3883","http://www.openwall.com/lists/oss-security/2015/05/21/6","https://www.cve.org/CVERecord?id=CVE-2015-1833"],"bugs":[""],"patches":{"jackrabbit":[]},"tags":{},"packages":[{"name":"jackrabbit","source":"https://ubuntu.com/security/cve?package=jackrabbit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackrabbit","debian":"https://tracker.debian.org/pkg/jackrabbit","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.3.6-1+deb8u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.10.1, 2.8.1, 2.6.6, 2.4.6, 2.2.14, 2.0.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2.3.6-1+deb8u1build0.14.10.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"2.3.6-1+deb8u1build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-0847","published":"2015-05-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnbd-server.c in Network Block Device (nbd-server) before 3.11 does not\nproperly handle signals, which allows remote attackers to cause a denial of\nservice (deadlock) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sourceforge.net/p/nbd/mailman/message/34091218/","https://ubuntu.com/security/notices/USN-2676-1","https://www.cve.org/CVERecord?id=CVE-2015-0847"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784657"],"patches":{"nbd":["upstream: http://sourceforge.net/p/nbd/mailman/message/34091218/","vendor: http://anonscm.debian.org/cgit/users/wouter/nbd.git/commit/?id=1c1481ee6faea00f32b9c83aa67e7cd70d15dad1","upstream: https://github.com/yoe/nbd/commit/412defe42d03be842c80d21dccf405c435b18432"]},"tags":{},"packages":[{"name":"nbd","source":"https://ubuntu.com/security/cve?package=nbd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nbd","debian":"https://tracker.debian.org/pkg/nbd","statuses":[{"release_codename":"precise","status":"released","description":"1:2.9.25-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:3.7-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:3.10-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1:3.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:3.8-4ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2676-1"],"notices":[{"id":"USN-2676-1","title":"NBD vulnerabilities","summary":"Several security issues were fixed in NBD.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-07-22T17:04:49.954548","description":"It was discovered that NBD incorrectly handled IP address matching. A\nremote attacker could use this issue with an IP address that has a partial\nmatch and bypass access restrictions. This issue only affected\nUbuntu 12.04 LTS. (CVE-2013-6410)\n\nTuomas Räsänen discovered that NBD incorrectly handled wrong export names\nand closed connections during negotiation. A remote attacker could use this\nissue to cause NBD to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2013-7441)\n\nTuomas Räsänen discovered that NBD incorrectly handled signals. A remote\nattacker could use this issue to cause NBD to crash, resulting in a denial\nof service. (CVE-2015-0847)\n","is_hidden":false,"release_packages":{"precise":[{"name":"nbd","version":"1:2.9.25-2ubuntu1.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-server","version":"1:2.9.25-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:2.9.25-2ubuntu1.1"}],"trusty":[{"name":"nbd","version":"1:3.7-1ubuntu0.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-client","version":"1:3.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.7-1ubuntu0.1","pocket":"security"},{"name":"nbd-client-udeb","version":"1:3.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.7-1ubuntu0.1","pocket":"security"},{"name":"nbd-server","version":"1:3.7-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.7-1ubuntu0.1","pocket":"security"}],"utopic":[{"name":"nbd","version":"1:3.8-1ubuntu0.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-server","version":"1:3.8-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.8-1ubuntu0.1"}],"vivid":[{"name":"nbd","version":"1:3.8-4ubuntu0.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-server","version":"1:3.8-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.8-4ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2013-6410","CVE-2013-7441","CVE-2015-0847"]}]},{"id":"CVE-2013-7441","published":"2015-05-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe modern style negotiation in Network Block Device (nbd-server) 2.9.22\nthrough 3.3 allows remote attackers to cause a denial of service (root\nprocess termination) by (1) closing the connection during negotiation or\n(2) specifying a name for a non-existent export.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/05/19/6","https://ubuntu.com/security/notices/USN-2676-1","https://www.cve.org/CVERecord?id=CVE-2013-7441"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781547"],"patches":{"nbd":["upstream: https://github.com/yoe/nbd/commit/741495cb08503fd32a9d22648e63b64390c601f4"]},"tags":{},"packages":[{"name":"nbd","source":"https://ubuntu.com/security/cve?package=nbd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nbd","debian":"https://tracker.debian.org/pkg/nbd","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:2.9.25-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1:3.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:3.4-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2676-1"],"notices":[{"id":"USN-2676-1","title":"NBD vulnerabilities","summary":"Several security issues were fixed in NBD.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-07-22T17:04:49.954548","description":"It was discovered that NBD incorrectly handled IP address matching. A\nremote attacker could use this issue with an IP address that has a partial\nmatch and bypass access restrictions. This issue only affected\nUbuntu 12.04 LTS. (CVE-2013-6410)\n\nTuomas Räsänen discovered that NBD incorrectly handled wrong export names\nand closed connections during negotiation. A remote attacker could use this\nissue to cause NBD to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2013-7441)\n\nTuomas Räsänen discovered that NBD incorrectly handled signals. A remote\nattacker could use this issue to cause NBD to crash, resulting in a denial\nof service. (CVE-2015-0847)\n","is_hidden":false,"release_packages":{"precise":[{"name":"nbd","version":"1:2.9.25-2ubuntu1.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-server","version":"1:2.9.25-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:2.9.25-2ubuntu1.1"}],"trusty":[{"name":"nbd","version":"1:3.7-1ubuntu0.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-client","version":"1:3.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.7-1ubuntu0.1","pocket":"security"},{"name":"nbd-client-udeb","version":"1:3.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.7-1ubuntu0.1","pocket":"security"},{"name":"nbd-server","version":"1:3.7-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.7-1ubuntu0.1","pocket":"security"}],"utopic":[{"name":"nbd","version":"1:3.8-1ubuntu0.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-server","version":"1:3.8-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.8-1ubuntu0.1"}],"vivid":[{"name":"nbd","version":"1:3.8-4ubuntu0.1","description":"Network Block Device protocol","is_source":true},{"name":"nbd-server","version":"1:3.8-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nbd","version_link":"https://launchpad.net/ubuntu/+source/nbd/1:3.8-4ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2013-6410","CVE-2013-7441","CVE-2015-0847"]}]},{"id":"CVE-2015-3906","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe logcat_dump_text function in wiretap/logcat.c in the Android Logcat\nfile parser in Wireshark 1.12.x before 1.12.5 does not properly handle a\nlack of \\0 termination, which allows remote attackers to cause a denial of\nservice (out-of-bounds read and application crash) via a crafted message in\na packet, a different vulnerability than CVE-2015-3815.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.wireshark.org/security/wnpa-sec-2015-18.html","https://www.cve.org/CVERecord?id=CVE-2015-3906"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11188"],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=b3b1f7c3aa2233a147294bad833b748d38fba84d"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3903","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x\nbefore 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables\nX.509 certificate verification for GitHub API calls over SSL, which allows\nman-in-the-middle attackers to spoof servers and obtain sensitive\ninformation via a crafted certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-3903"],"bugs":[""],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"vivid","status":"released","description":"4:4.2.12-2+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3902","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site request forgery (CSRF) vulnerabilities in the setup\nprocess in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x\nbefore 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack\nthe authentication of administrators for requests that modify the\nconfiguration file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-3902"],"bugs":[""],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"vivid","status":"released","description":"4:4.2.12-2+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4:4.4.6.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3815","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe detect_version function in wiretap/logcat.c in the Android Logcat file\nparser in Wireshark 1.12.x before 1.12.5 does not check the length of the\npayload, which allows remote attackers to cause a denial of service\n(out-of-bounds read and application crash) via a packet with a crafted\npayload, as demonstrated by a length of zero, a different vulnerability\nthan CVE-2015-3906.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-18.html","https://blog.fuzzing-project.org/11-Read-heap-overflow-invalid-memory-access-in-Wireshark-TFPA-0072015.html","https://www.cve.org/CVERecord?id=CVE-2015-3815"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11188"],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=b3b1f7c3aa2233a147294bad833b748d38fba84d"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3814","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) dissect_tfs_request and (2) dissect_tfs_response functions in\nepan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in\nWireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero\nvalue as a length rather than an error condition, which allows remote\nattackers to cause a denial of service (infinite loop) via a crafted\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-17.html","https://www.cve.org/CVERecord?id=CVE-2015-3814"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11110"],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=e243b0041328980a9bbd43bb8a8166d7422f9096"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3813","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe fragment_add_work function in epan/reassemble.c in the\npacket-reassembly feature in Wireshark 1.12.x before 1.12.5 does not\nproperly determine the defragmentation state in a case of an insufficient\nsnapshot length, which allows remote attackers to cause a denial of service\n(memory consumption) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-16.html","https://www.cve.org/CVERecord?id=CVE-2015-3813"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11129"],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=c35f2ccb4433718416551cc7a85afb0860529d57"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3812","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple memory leaks in the x11_init_protocol function in\nepan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x\nbefore 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a\ndenial of service (memory consumption) via a crafted packet.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"\"Affected versions: 1.12.0 to 1.12.4, 1.10.0 to 1.10.13\""}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-15.html","https://www.cve.org/CVERecord?id=CVE-2015-3812"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11088"],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=b8ccc2a6add29823a0ff0492fc50372449007e7b"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3811","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nepan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x\nbefore 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously\nprocessed bytes, which allows remote attackers to cause a denial of service\n(application crash) via a crafted packet, a different vulnerability than\nCVE-2015-2188.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"\"Affected versions: 1.12.0 to 1.12.4, 1.10.0 to 1.10.13\""}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-14.html","https://www.cve.org/CVERecord?id=CVE-2015-3811"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10978"],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=a6fc6aa0b4efc1a1c3d7a2e3b5189e888fb6ccc2"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3810","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nepan/dissectors/packet-websocket.c in the WebSocket dissector in Wireshark\n1.12.x before 1.12.5 uses a recursive algorithm, which allows remote\nattackers to cause a denial of service (CPU consumption) via a crafted\npacket.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"\"Affected versions: 1.12.0 to 1.12.4\""}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.wireshark.org/security/wnpa-sec-2015-13.html","https://www.cve.org/CVERecord?id=CVE-2015-3810"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10989"],"patches":{"wireshark":["upstream: https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=4ee6bcbd2e03a25f1e6b0239558d9edeaf8040c0"]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1build0.15.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3809","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR\ndissector in Wireshark 1.12.x before 1.12.5 does not properly track the\ncurrent offset, which allows remote attackers to cause a denial of service\n(infinite loop) via a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11036","https://www.wireshark.org/security/wnpa-sec-2015-12.html","https://www.cve.org/CVERecord?id=CVE-2015-3809"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1build0.15.04.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3808","published":"2015-05-26T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR\ndissector in Wireshark 1.12.x before 1.12.5 does not reject a zero length,\nwhich allows remote attackers to cause a denial of service (infinite loop)\nvia a crafted packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11036","https://www.wireshark.org/security/wnpa-sec-2015-12.html","https://www.cve.org/CVERecord?id=CVE-2015-3808"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+g01b65bf-4+deb8u1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.5+g5819e5b-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3905","published":"2015-05-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the set_cs_start function in t1disasm.c in t1utils\nbefore 1.39 allows remote attackers to cause a denial of service (crash)\nand possibly execute arbitrary code via a crafted font file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/05/13/9","https://ubuntu.com/security/notices/USN-2627-1","https://www.cve.org/CVERecord?id=CVE-2015-3905"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=779274","https://github.com/kohler/t1utils/issues/4","https://bugzilla.redhat.com/show_bug.cgi?id=1218365"],"patches":{"t1utils":["upstream: https://github.com/kohler/t1utils/commit/6b9d1aafcb61a3663c883663eb19ccdbfcde8d33"]},"tags":{},"packages":[{"name":"t1utils","source":"https://ubuntu.com/security/cve?package=t1utils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=t1utils","debian":"https://tracker.debian.org/pkg/t1utils","statuses":[{"release_codename":"precise","status":"released","description":"1.37-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.37-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.38-4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.37-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.38-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-2627-1"],"notices":[{"id":"USN-2627-1","title":"t1utils vulnerability","summary":"t1utils could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-06-03T17:52:47.872809","description":"Jakub Wilk discovered that t1utils incorrectly handled certain malformed fonts.\nIf a user or automated system were tricked into opening a specially crafted\nfont, a remote attacker could crash the application, leading to a denial of\nservice, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"t1utils","version":"1.37-2ubuntu1.1","description":"Collection of simple Type 1 font manipulation programs","is_source":true},{"name":"t1utils","version":"1.37-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/t1utils","version_link":"https://launchpad.net/ubuntu/+source/t1utils/1.37-2ubuntu1.1","pocket":"security"}],"utopic":[{"name":"t1utils","version":"1.37-2.1ubuntu0.1","description":"Collection of simple Type 1 font manipulation programs","is_source":true},{"name":"t1utils","version":"1.37-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/t1utils","version_link":"https://launchpad.net/ubuntu/+source/t1utils/1.37-2.1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2015-3905"]}]},{"id":"CVE-2015-2694","published":"2015-05-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x\nbefore 1.13.2 do not properly track whether a client's request has been\nvalidated, which allows remote attackers to bypass an intended\npreauthentication requirement by providing (1) zero bytes of data or (2) an\narbitrary realm name, related to plugins/preauth/otp/main.c and\nplugins/preauth/pkinit/pkinit_srv.c.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"affects 1.12 and later"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2810-1","https://www.cve.org/CVERecord?id=CVE-2015-2694"],"bugs":["http://krbdev.mit.edu/rt/Ticket/Display.html?id=8160","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=783557"],"patches":{"krb5":["upstream: https://github.com/krb5/krb5/commit/e3b5a5e5267818c97750b266df50b6a3d4649604"]},"tags":{"krb5":["universe-binary"]},"packages":[{"name":"krb5","source":"https://ubuntu.com/security/cve?package=krb5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=krb5","debian":"https://tracker.debian.org/pkg/krb5","statuses":[{"release_codename":"lucid","status":"not-affected","description":"1.8.1+dfsg-2ubuntu0.14","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.10+dfsg~beta1-2ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.12+dfsg-2ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.13.2,1.12.1+dfsg-20","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.12.1+dfsg-18ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.13.2+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2810-1"],"notices":[{"id":"USN-2810-1","title":"Kerberos vulnerabilities","summary":"Several security issues were fixed in Kerberos.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-11-12T17:50:55.940907","description":"It was discovered that the Kerberos kpasswd service incorrectly handled\ncertain UDP packets. A remote attacker could possibly use this issue to\ncause resource consumption, resulting in a denial of service. This issue\nonly affected Ubuntu 12.04 LTS. (CVE-2002-2443)\n\nIt was discovered that Kerberos incorrectly handled null bytes in certain\ndata fields. A remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-5355)\n\nIt was discovered that the Kerberos kdcpreauth modules incorrectly tracked\ncertain client requests. A remote attacker could possibly use this issue\nto bypass intended preauthentication requirements. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-2694)\n\nIt was discovered that Kerberos incorrectly handled certain SPNEGO packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2695)\n\nIt was discovered that Kerberos incorrectly handled certain IAKERB packets.\nA remote attacker could possibly use this issue to cause a denial of\nservice. (CVE-2015-2696, CVE-2015-2698)\n\nIt was discovered that Kerberos incorrectly handled certain TGS requests. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2015-2697)\n","is_hidden":false,"release_packages":{"precise":[{"name":"krb5","version":"1.10+dfsg~beta1-2ubuntu0.7","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-kdc-ldap","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-pkinit","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"krb5-user","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssapi-krb5-2","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libgssrpc4","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libk5crypto3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkadm5clnt-mit8","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkdb5-6","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5-3","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb53","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"},{"name":"libkrb5support0","version":"1.10+dfsg~beta1-2ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.10+dfsg~beta1-2ubuntu0.7"}],"trusty":[{"name":"krb5","version":"1.12+dfsg-2ubuntu5.2","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-doc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-gss-samples","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-kdc-ldap","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-locales","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-multidev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-otp","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-pkinit","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"krb5-user","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssapi-krb5-2","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libgssrpc4","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libk5crypto3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5clnt-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit8","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkadm5srv-mit9","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkdb5-7","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrad0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-3","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5-dev","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"},{"name":"libkrb5support0","version":"1.12+dfsg-2ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12+dfsg-2ubuntu5.2","pocket":"security"}],"vivid":[{"name":"krb5","version":"1.12.1+dfsg-18ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-otp","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-pkinit","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"krb5-user","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libgssrpc4","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libk5crypto3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkdb5-7","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrad0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5-3","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"},{"name":"libkrb5support0","version":"1.12.1+dfsg-18ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.12.1+dfsg-18ubuntu0.1"}],"wily":[{"name":"krb5","version":"1.13.2+dfsg-2ubuntu0.1","description":"MIT Kerberos Network Authentication Protocol","is_source":true},{"name":"krb5-admin-server","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-k5tls","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-kdc-ldap","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-otp","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-pkinit","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"krb5-user","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssapi-krb5-2","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libgssrpc4","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libk5crypto3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkadm5clnt-mit9","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkdb5-8","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrad0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5-3","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"},{"name":"libkrb5support0","version":"1.13.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/krb5","version_link":"https://launchpad.net/ubuntu/+source/krb5/1.13.2+dfsg-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2002-2443","CVE-2014-5355","CVE-2015-2694","CVE-2015-2695","CVE-2015-2696","CVE-2015-2697","CVE-2015-2698"]}]},{"id":"CVE-2015-4037","published":"2015-05-23T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates\ntemporary files with predictable names, which allows local users to cause a\ndenial of service (instantiation failure) by creating /tmp/qemu-smb.*-*\nfiles before the program.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/05/23/4","https://ubuntu.com/security/notices/USN-2630-1","https://www.cve.org/CVERecord?id=CVE-2015-4037"],"bugs":[""],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=8b8f1c7e9ddb2e88a144638f6527bf70e32343e3"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2.1+dfsg-4ubuntu6.7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1:2.2+dfsg-5expubuntu9.2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.23","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2630-1"],"notices":[{"id":"USN-2630-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2015-06-10T14:30:07.103508","description":"Matt Tait discovered that QEMU incorrectly handled the virtual PCNET\ndriver. A malicious guest could use this issue to cause a denial of\nservice, or possibly execute arbitrary code on the host as the user running\nthe QEMU process. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2015-3209)\n\nKurt Seifried discovered that QEMU incorrectly handled certain temporary\nfiles. A local attacker could use this issue to cause a denial of service.\n(CVE-2015-4037)\n\nJan Beulich discovered that the QEMU Xen code incorrectly restricted write\naccess to the host MSI message data field. A malicious guest could use this\nissue to cause a denial of service. This issue only applied to Ubuntu 14.04\nLTS, Ubuntu 14.10 and Ubuntu 15.04. (CVE-2015-4103)\n\nJan Beulich discovered that the QEMU Xen code incorrectly restricted access\nto the PCI MSI mask bits. A malicious guest could use this issue to cause a\ndenial of service. This issue only applied to Ubuntu 14.04 LTS, Ubuntu\n14.10 and Ubuntu 15.04. (CVE-2015-4104)\n\nJan Beulich discovered that the QEMU Xen code incorrectly handled MSI-X\nerror messages. A malicious guest could use this issue to cause a denial of\nservice. This issue only applied to Ubuntu 14.04 LTS, Ubuntu 14.10 and\nUbuntu 15.04. (CVE-2015-4105)\n\nJan Beulich discovered that the QEMU Xen code incorrectly restricted write\naccess to the PCI config space. A malicious guest could use this issue to\ncause a denial of service, obtain sensitive information, or possibly\nexecute arbitrary code. This issue only applied to Ubuntu 14.04 LTS,\nUbuntu 14.10 and Ubuntu 15.04. (CVE-2015-4106)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.23","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.23"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.13","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.13","pocket":"security"}],"utopic":[{"name":"qemu","version":"2.1+dfsg-4ubuntu6.7","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"},{"name":"qemu-system-aarch64","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"},{"name":"qemu-system-arm","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"},{"name":"qemu-system-mips","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"},{"name":"qemu-system-misc","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"},{"name":"qemu-system-ppc","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"},{"name":"qemu-system-sparc","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"},{"name":"qemu-system-x86","version":"2.1+dfsg-4ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.7"}],"vivid":[{"name":"qemu","version":"1:2.2+dfsg-5expubuntu9.2","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"},{"name":"qemu-system-aarch64","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"},{"name":"qemu-system-arm","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"},{"name":"qemu-system-mips","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"},{"name":"qemu-system-misc","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"},{"name":"qemu-system-ppc","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"},{"name":"qemu-system-sparc","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"},{"name":"qemu-system-x86","version":"1:2.2+dfsg-5expubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.2+dfsg-5expubuntu9.2"}]},"type":"USN","cves_ids":["CVE-2015-3209","CVE-2015-4037","CVE-2015-4103","CVE-2015-4104","CVE-2015-4105","CVE-2015-4106"]}]},{"id":"CVE-2015-0916","published":"2015-05-22T00:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSQL injection vulnerability in graph.php in Cacti before 0.8.6f allows\nremote authenticated users to execute arbitrary SQL commands via the\nlocal_graph_id parameter, a different vulnerability than CVE-2007-6035.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.cacti.net/release_notes_0_8_6f.php","http://jvndb.jvn.jp/jvndb/JVNDB-2015-000064","http://jvn.jp/en/jp/JVN18957556/index.html","https://www.cve.org/CVERecord?id=CVE-2015-0916"],"bugs":[""],"patches":{"cacti":[]},"tags":{},"packages":[{"name":"cacti","source":"https://ubuntu.com/security/cve?package=cacti","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cacti","debian":"https://tracker.debian.org/pkg/cacti","statuses":[{"release_codename":"precise","status":"not-affected","description":"0.8.7i-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"0.8.7i-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6f","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"0.8.7i-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"0.8.7i-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4047","published":"2015-05-22T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nracoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a\ndenial of service (NULL pointer dereference and IKE daemon crash) via a\nseries of crafted UDP requests.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"reported against ipsec-tools 0.8.2"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/05/20/1","http://seclists.org/fulldisclosure/2015/May/81","http://seclists.org/fulldisclosure/2015/May/83","https://ubuntu.com/security/notices/USN-2623-1","https://www.cve.org/CVERecord?id=CVE-2015-4047"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=785778"],"patches":{"ipsec-tools":[]},"tags":{},"packages":[{"name":"ipsec-tools","source":"https://ubuntu.com/security/cve?package=ipsec-tools","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ipsec-tools","debian":"https://tracker.debian.org/pkg/ipsec-tools","statuses":[{"release_codename":"precise","status":"released","description":"1:0.8.0-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:0.8.0-14+deb7u1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:0.8.2+20140711-3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:0.8.2+20140711-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:0.8.2+20140711-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2623-1"],"notices":[{"id":"USN-2623-1","title":"ipsec-tools vulnerability","summary":"ipsec-tools could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-06-01T16:58:37.829103","description":"It was discovered that racoon, the ipsec-tools IKE daemon, incorrectly\nhandled certain UDP packets. A remote attacker could use this issue to\ncause racoon to crash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"precise":[{"name":"ipsec-tools","version":"1:0.8.0-9ubuntu1.1","description":"IPsec tools for Linux","is_source":true},{"name":"racoon","version":"1:0.8.0-9ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ipsec-tools","version_link":"https://launchpad.net/ubuntu/+source/ipsec-tools/1:0.8.0-9ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2015-4047"]}]}],"offset":63320,"limit":20,"total_results":79316}