{"cves":[{"id":"CVE-2014-8096","published":"2014-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X\nWindow System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and\nxorg-server) before 1.16.3 allows remote authenticated users to cause a\ndenial of service (out-of-bounds read or write) or possibly execute\narbitrary code via a crafted length or index value.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/","https://ubuntu.com/security/notices/USN-2436-1","https://www.cve.org/CVERecord?id=CVE-2014-8096"],"bugs":[""],"patches":{"xorg-server":[],"xorg-server-lts-trusty":[]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.11.4-0ubuntu10.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:1.15.1-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.16.2.901-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2:1.16.0-1ubuntu1.1","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-trusty","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-trusty","debian":"https://tracker.debian.org/pkg/xorg-server-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.15.1-0ubuntu2~precise3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2436-1"],"notices":[{"id":"USN-2436-1","title":"X.Org X server vulnerabilities","summary":"Several security issues were fixed in the X.Org X server.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-09T18:36:18.207361","description":"Ilja van Sprundel discovered a multitude of security issues in the X.Org X\nserver. An attacker able to connect to an X server, either locally or\nremotely, could use these issues to cause the X server to crash or execute\narbitrary code resulting in possible privilege escalation.\n","is_hidden":false,"release_packages":{"precise":[{"name":"xorg-server","version":"2:1.11.4-0ubuntu10.15","description":"X.Org X11 server","is_source":true},{"name":"xorg-server-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.11.4-0ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.11.4-0ubuntu10.15"},{"name":"xserver-xorg-core-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty/2:1.15.1-0ubuntu2~precise3"}],"trusty":[{"name":"xorg-server","version":"2:1.15.1-0ubuntu2.4","description":"X.Org X11 server","is_source":true},{"name":"xdmx","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xdmx-tools","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xnest","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xorg-server-source","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-common","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xephyr","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core-udeb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-dev","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-xmir","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xvfb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"}],"utopic":[{"name":"xorg-server","version":"2:1.16.0-1ubuntu1.1","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.16.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.16.0-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-8091","CVE-2014-8092","CVE-2014-8093","CVE-2014-8094","CVE-2014-8095","CVE-2014-8096","CVE-2014-8097","CVE-2014-8098","CVE-2014-8099","CVE-2014-8100","CVE-2014-8101","CVE-2014-8102","CVE-2014-8103"]}]},{"id":"CVE-2014-8095","published":"2014-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe XInput extension in X.Org X Window System (aka X11 or X) X11R4 and\nX.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote\nauthenticated users to cause a denial of service (out-of-bounds read or\nwrite) or possibly execute arbitrary code via a crafted length or index\nvalue to the (1) SProcXChangeDeviceControl, (2) ProcXChangeDeviceControl,\n(3) ProcXChangeFeedbackControl, (4) ProcXSendExtensionEvent, (5)\nSProcXIAllowEvents, (6) SProcXIChangeCursor, (7) ProcXIChangeHierarchy, (8)\nSProcXIGetClientPointer, (9) SProcXIGrabDevice, (10) SProcXIUngrabDevice,\n(11) ProcXIUngrabDevice, (12) SProcXIPassiveGrabDevice, (13)\nProcXIPassiveGrabDevice, (14) SProcXIPassiveUngrabDevice, (15)\nProcXIPassiveUngrabDevice, (16) SProcXListDeviceProperties, (17)\nSProcXDeleteDeviceProperty, (18) SProcXIListProperties, (19)\nSProcXIDeleteProperty, (20) SProcXIGetProperty, (21) SProcXIQueryDevice,\n(22) SProcXIQueryPointer, (23) SProcXISelectEvents, (24)\nSProcXISetClientPointer, (25) SProcXISetFocus, (26) SProcXIGetFocus, or\n(27) SProcXIWarpPointer function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/","https://ubuntu.com/security/notices/USN-2436-1","https://www.cve.org/CVERecord?id=CVE-2014-8095"],"bugs":[""],"patches":{"xorg-server":[],"xorg-server-lts-trusty":[]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.11.4-0ubuntu10.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:1.15.1-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.16.2.901-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2:1.16.0-1ubuntu1.1","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-trusty","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-trusty","debian":"https://tracker.debian.org/pkg/xorg-server-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.15.1-0ubuntu2~precise3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2436-1"],"notices":[{"id":"USN-2436-1","title":"X.Org X server vulnerabilities","summary":"Several security issues were fixed in the X.Org X server.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-09T18:36:18.207361","description":"Ilja van Sprundel discovered a multitude of security issues in the X.Org X\nserver. An attacker able to connect to an X server, either locally or\nremotely, could use these issues to cause the X server to crash or execute\narbitrary code resulting in possible privilege escalation.\n","is_hidden":false,"release_packages":{"precise":[{"name":"xorg-server","version":"2:1.11.4-0ubuntu10.15","description":"X.Org X11 server","is_source":true},{"name":"xorg-server-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.11.4-0ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.11.4-0ubuntu10.15"},{"name":"xserver-xorg-core-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty/2:1.15.1-0ubuntu2~precise3"}],"trusty":[{"name":"xorg-server","version":"2:1.15.1-0ubuntu2.4","description":"X.Org X11 server","is_source":true},{"name":"xdmx","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xdmx-tools","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xnest","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xorg-server-source","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-common","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xephyr","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core-udeb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-dev","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-xmir","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xvfb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"}],"utopic":[{"name":"xorg-server","version":"2:1.16.0-1ubuntu1.1","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.16.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.16.0-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-8091","CVE-2014-8092","CVE-2014-8093","CVE-2014-8094","CVE-2014-8095","CVE-2014-8096","CVE-2014-8097","CVE-2014-8098","CVE-2014-8099","CVE-2014-8100","CVE-2014-8101","CVE-2014-8102","CVE-2014-8103"]}]},{"id":"CVE-2014-8094","published":"2014-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the ProcDRI2GetBuffers function in the DRI2 extension\nin X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before\n1.16.3 allows remote authenticated users to cause a denial of service\n(crash) or possibly execute arbitrary code via a crafted request, which\ntriggers an out-of-bounds read or write.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/","https://ubuntu.com/security/notices/USN-2436-1","https://www.cve.org/CVERecord?id=CVE-2014-8094"],"bugs":[""],"patches":{"xorg-server":[],"xorg-server-lts-trusty":[]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.11.4-0ubuntu10.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:1.15.1-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.16.2.901-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2:1.16.0-1ubuntu1.1","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-trusty","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-trusty","debian":"https://tracker.debian.org/pkg/xorg-server-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.15.1-0ubuntu2~precise3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2436-1"],"notices":[{"id":"USN-2436-1","title":"X.Org X server vulnerabilities","summary":"Several security issues were fixed in the X.Org X server.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-09T18:36:18.207361","description":"Ilja van Sprundel discovered a multitude of security issues in the X.Org X\nserver. An attacker able to connect to an X server, either locally or\nremotely, could use these issues to cause the X server to crash or execute\narbitrary code resulting in possible privilege escalation.\n","is_hidden":false,"release_packages":{"precise":[{"name":"xorg-server","version":"2:1.11.4-0ubuntu10.15","description":"X.Org X11 server","is_source":true},{"name":"xorg-server-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.11.4-0ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.11.4-0ubuntu10.15"},{"name":"xserver-xorg-core-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty/2:1.15.1-0ubuntu2~precise3"}],"trusty":[{"name":"xorg-server","version":"2:1.15.1-0ubuntu2.4","description":"X.Org X11 server","is_source":true},{"name":"xdmx","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xdmx-tools","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xnest","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xorg-server-source","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-common","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xephyr","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core-udeb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-dev","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-xmir","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xvfb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"}],"utopic":[{"name":"xorg-server","version":"2:1.16.0-1ubuntu1.1","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.16.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.16.0-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-8091","CVE-2014-8092","CVE-2014-8093","CVE-2014-8094","CVE-2014-8095","CVE-2014-8096","CVE-2014-8097","CVE-2014-8098","CVE-2014-8099","CVE-2014-8100","CVE-2014-8101","CVE-2014-8102","CVE-2014-8103"]}]},{"id":"CVE-2014-8093","published":"2014-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in the GLX extension in XFree86 4.0, X.Org X\nWindow System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and\nxorg-server) before 1.16.3 allow remote authenticated users to cause a\ndenial of service (crash) or possibly execute arbitrary code via a crafted\nrequest to the (1) __glXDisp_ReadPixels, (2) __glXDispSwap_ReadPixels, (3)\n__glXDisp_GetTexImage, (4) __glXDispSwap_GetTexImage, (5)\nGetSeparableFilter, (6) GetConvolutionFilter, (7) GetHistogram, (8)\nGetMinmax, (9) GetColorTable, (10) __glXGetAnswerBuffer, (11)\n__GLX_GET_ANSWER_BUFFER, (12) __glXMap1dReqSize, (13) __glXMap1fReqSize,\n(14) Map2Size, (15) __glXMap2dReqSize, (16) __glXMap2fReqSize, (17)\n__glXImageSize, or (18) __glXSeparableFilter2DReqSize function, which\ntriggers an out-of-bounds read or write.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/","https://ubuntu.com/security/notices/USN-2436-1","https://www.cve.org/CVERecord?id=CVE-2014-8093"],"bugs":[""],"patches":{"xorg-server":[],"xorg-server-lts-trusty":[]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.11.4-0ubuntu10.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:1.15.1-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.16.2.901-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2:1.16.0-1ubuntu1.1","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-trusty","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-trusty","debian":"https://tracker.debian.org/pkg/xorg-server-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.15.1-0ubuntu2~precise3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2436-1"],"notices":[{"id":"USN-2436-1","title":"X.Org X server vulnerabilities","summary":"Several security issues were fixed in the X.Org X server.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-09T18:36:18.207361","description":"Ilja van Sprundel discovered a multitude of security issues in the X.Org X\nserver. An attacker able to connect to an X server, either locally or\nremotely, could use these issues to cause the X server to crash or execute\narbitrary code resulting in possible privilege escalation.\n","is_hidden":false,"release_packages":{"precise":[{"name":"xorg-server","version":"2:1.11.4-0ubuntu10.15","description":"X.Org X11 server","is_source":true},{"name":"xorg-server-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.11.4-0ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.11.4-0ubuntu10.15"},{"name":"xserver-xorg-core-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty/2:1.15.1-0ubuntu2~precise3"}],"trusty":[{"name":"xorg-server","version":"2:1.15.1-0ubuntu2.4","description":"X.Org X11 server","is_source":true},{"name":"xdmx","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xdmx-tools","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xnest","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xorg-server-source","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-common","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xephyr","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core-udeb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-dev","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-xmir","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xvfb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"}],"utopic":[{"name":"xorg-server","version":"2:1.16.0-1ubuntu1.1","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.16.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.16.0-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-8091","CVE-2014-8092","CVE-2014-8093","CVE-2014-8094","CVE-2014-8095","CVE-2014-8096","CVE-2014-8097","CVE-2014-8098","CVE-2014-8099","CVE-2014-8100","CVE-2014-8101","CVE-2014-8102","CVE-2014-8103"]}]},{"id":"CVE-2014-8092","published":"2014-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in X.Org X Window System (aka X11 or X) X11R1\nand X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote\nauthenticated users to cause a denial of service (crash) or possibly\nexecute arbitrary code via a crafted request to the (1) ProcPutImage, (2)\nGetHosts, (3) RegionSizeof, or (4) REQUEST_FIXED_SIZE function, which\ntriggers an out-of-bounds read or write.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/","https://ubuntu.com/security/notices/USN-2436-1","https://www.cve.org/CVERecord?id=CVE-2014-8092"],"bugs":[""],"patches":{"xorg-server":[],"xorg-server-lts-trusty":[]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.11.4-0ubuntu10.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:1.15.1-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.16.2.901-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2:1.16.0-1ubuntu1.1","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-trusty","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-trusty","debian":"https://tracker.debian.org/pkg/xorg-server-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.15.1-0ubuntu2~precise3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2436-1"],"notices":[{"id":"USN-2436-1","title":"X.Org X server vulnerabilities","summary":"Several security issues were fixed in the X.Org X server.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-09T18:36:18.207361","description":"Ilja van Sprundel discovered a multitude of security issues in the X.Org X\nserver. An attacker able to connect to an X server, either locally or\nremotely, could use these issues to cause the X server to crash or execute\narbitrary code resulting in possible privilege escalation.\n","is_hidden":false,"release_packages":{"precise":[{"name":"xorg-server","version":"2:1.11.4-0ubuntu10.15","description":"X.Org X11 server","is_source":true},{"name":"xorg-server-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.11.4-0ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.11.4-0ubuntu10.15"},{"name":"xserver-xorg-core-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty/2:1.15.1-0ubuntu2~precise3"}],"trusty":[{"name":"xorg-server","version":"2:1.15.1-0ubuntu2.4","description":"X.Org X11 server","is_source":true},{"name":"xdmx","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xdmx-tools","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xnest","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xorg-server-source","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-common","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xephyr","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core-udeb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-dev","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-xmir","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xvfb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"}],"utopic":[{"name":"xorg-server","version":"2:1.16.0-1ubuntu1.1","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.16.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.16.0-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-8091","CVE-2014-8092","CVE-2014-8093","CVE-2014-8094","CVE-2014-8095","CVE-2014-8096","CVE-2014-8097","CVE-2014-8098","CVE-2014-8099","CVE-2014-8100","CVE-2014-8101","CVE-2014-8102","CVE-2014-8103"]}]},{"id":"CVE-2014-8091","published":"2014-12-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nX.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver\nand xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC)\nauthentication credentials, does not check the return value of a malloc\ncall, which allows remote attackers to cause a denial of service (NULL\npointer dereference and server crash) via a crafted connection request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.x.org/wiki/Development/Security/Advisory-2014-12-09/","http://nvidia.custhelp.com/app/answers/detail/a_id/3610/kw/3610","https://ubuntu.com/security/notices/USN-2436-1","https://ubuntu.com/security/notices/USN-2438-1","https://www.cve.org/CVERecord?id=CVE-2014-8091"],"bugs":[""],"patches":{"xorg-server":[],"xorg-server-lts-trusty":[],"nvidia-graphics-drivers-304":[],"nvidia-graphics-drivers-304-updates":[],"nvidia-graphics-drivers-331":[],"nvidia-graphics-drivers-331-updates":[]},"tags":{},"packages":[{"name":"nvidia-graphics-drivers-304","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-304","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-304","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-304","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"304.125-0ubuntu0.0.0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"304.125-0ubuntu0.0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"304.125","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"304.125-0ubuntu0.1","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-304-updates","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-304-updates","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-304-updates","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-304-updates","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"304.125-0ubuntu0.0.0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"304.125-0ubuntu0.0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"304.125","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"304.125-0ubuntu0.1","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-331","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-331","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-331","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-331","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"331.113-0ubuntu0.0.0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"331.113-0ubuntu0.0.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"331.113","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"331.113-0ubuntu0.1","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-331-updates","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-331-updates","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-331-updates","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-331-updates","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"331.113-0ubuntu0.0.0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"331.113-0ubuntu0.0.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"331.113","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"331.113-0ubuntu0.1","component":null,"pocket":"security"}]},{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.11.4-0ubuntu10.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:1.15.1-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.16.2.901-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2:1.16.0-1ubuntu1.1","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-trusty","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-trusty","debian":"https://tracker.debian.org/pkg/xorg-server-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.15.1-0ubuntu2~precise3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2438-1","USN-2436-1"],"notices":[{"id":"USN-2438-1","title":"NVIDIA graphics drivers vulnerabilities","summary":"Several security issues were fixed in the NVIDIA graphics drivers.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-10T18:35:36.157169","description":"It was discovered that the NVIDIA graphics drivers incorrectly handled GLX\nindirect rendering support. An attacker able to connect to an X server,\neither locally or remotely, could use these issues to cause the X server to\ncrash or execute arbitrary code resulting in possible privilege escalation.\n","is_hidden":false,"release_packages":{"precise":[{"name":"nvidia-graphics-drivers-304","version":"304.125-0ubuntu0.0.0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-304-updates","version":"304.125-0ubuntu0.0.0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-331","version":"331.113-0ubuntu0.0.0.3","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-331-updates","version":"331.113-0ubuntu0.0.0.3","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-304","version":"304.125-0ubuntu0.0.0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.0.1"},{"name":"nvidia-304-updates","version":"304.125-0ubuntu0.0.0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.0.1"},{"name":"nvidia-331","version":"331.113-0ubuntu0.0.0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.0.3"},{"name":"nvidia-331-updates","version":"331.113-0ubuntu0.0.0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.0.3"}],"trusty":[{"name":"nvidia-graphics-drivers-304","version":"304.125-0ubuntu0.0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-304-updates","version":"304.125-0ubuntu0.0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-331","version":"331.113-0ubuntu0.0.4","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-331-updates","version":"331.113-0ubuntu0.0.4","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"libcuda1-304","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"libcuda1-304-updates","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"libcuda1-331","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"libcuda1-331-updates","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-304","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-304-dev","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-304-updates","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-304-updates-dev","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-319","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-319-dev","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-319-updates","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-319-updates-dev","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-331","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-331-dev","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-331-updates","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-331-updates-dev","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-331-updates-uvm","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-331-uvm","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-current","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-current-dev","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-current-updates","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-current-updates-dev","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-experimental-304","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-experimental-304-dev","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-libopencl1-304","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-libopencl1-304-updates","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-libopencl1-331","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-libopencl1-331-updates","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-opencl-icd-304","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-opencl-icd-304-updates","version":"304.125-0ubuntu0.0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.0.1","pocket":"security"},{"name":"nvidia-opencl-icd-331","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"},{"name":"nvidia-opencl-icd-331-updates","version":"331.113-0ubuntu0.0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.0.4","pocket":"security"}],"utopic":[{"name":"nvidia-graphics-drivers-304","version":"304.125-0ubuntu0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-304-updates","version":"304.125-0ubuntu0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-331","version":"331.113-0ubuntu0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-graphics-drivers-331-updates","version":"331.113-0ubuntu0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-304","version":"304.125-0ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.1"},{"name":"nvidia-304-updates","version":"304.125-0ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.125-0ubuntu0.1"},{"name":"nvidia-331","version":"331.113-0ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.1"},{"name":"nvidia-331-updates","version":"331.113-0ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-331/331.113-0ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2014-8091","CVE-2014-8098","CVE-2014-8298"]},{"id":"USN-2436-1","title":"X.Org X server vulnerabilities","summary":"Several security issues were fixed in the X.Org X server.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-09T18:36:18.207361","description":"Ilja van Sprundel discovered a multitude of security issues in the X.Org X\nserver. An attacker able to connect to an X server, either locally or\nremotely, could use these issues to cause the X server to crash or execute\narbitrary code resulting in possible privilege escalation.\n","is_hidden":false,"release_packages":{"precise":[{"name":"xorg-server","version":"2:1.11.4-0ubuntu10.15","description":"X.Org X11 server","is_source":true},{"name":"xorg-server-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.11.4-0ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.11.4-0ubuntu10.15"},{"name":"xserver-xorg-core-lts-trusty","version":"2:1.15.1-0ubuntu2~precise3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-trusty/2:1.15.1-0ubuntu2~precise3"}],"trusty":[{"name":"xorg-server","version":"2:1.15.1-0ubuntu2.4","description":"X.Org X11 server","is_source":true},{"name":"xdmx","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xdmx-tools","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xnest","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xorg-server-source","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-common","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xephyr","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-core-udeb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-dev","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xserver-xorg-xmir","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"},{"name":"xvfb","version":"2:1.15.1-0ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1-0ubuntu2.4","pocket":"security"}],"utopic":[{"name":"xorg-server","version":"2:1.16.0-1ubuntu1.1","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.16.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.16.0-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-8091","CVE-2014-8092","CVE-2014-8093","CVE-2014-8094","CVE-2014-8095","CVE-2014-8096","CVE-2014-8097","CVE-2014-8098","CVE-2014-8099","CVE-2014-8100","CVE-2014-8101","CVE-2014-8102","CVE-2014-8103"]}]},{"id":"CVE-2014-9280","published":"2014-12-08T16:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe current_user_get_bug_filter function in core/current_user_api.php in\nMantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP\ncode via the filter parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://github.com/mantisbt/mantisbt/commit/599364b2","http://www.mantisbt.org/bugs/view.php?id=17875","https://github.com/mantisbt/mantisbt/commit/599364b2","http://xforce.iss.net/xforce/xfdb/99016","http://seclists.org/oss-sec/2014/q4/923","http://seclists.org/oss-sec/2014/q4/864","https://www.cve.org/CVERecord?id=CVE-2014-9280"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9279","published":"2014-12-08T16:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe print_test_result function in admin/upgrade_unattended.php in MantisBT\n1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain\ndatabase credentials via a URL in the hostname parameter and reading the\nparameters in the response sent to the URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://github.com/mantisbt/mantisbt/commit/0826cef8","http://www.mantisbt.org/bugs/view.php?id=17877","https://github.com/mantisbt/mantisbt/commit/0826cef8","http://xforce.iss.net/xforce/xfdb/99031","http://seclists.org/oss-sec/2014/q4/863","https://www.cve.org/CVERecord?id=CVE-2014-9279"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9273","published":"2014-12-08T16:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary\ncode and gain privileges via a small hive files, which triggers an\nout-of-bounds read or write.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/libguestfs/hivex/commit/357f26fa64fd1d9ccac2331fe174a8ee9c607adb","https://github.com/libguestfs/hivex/commit/4bbdf555f88baeae0fa804a369a81a83908bd705","https://www.cve.org/CVERecord?id=CVE-2014-9273"],"bugs":[""],"patches":{"hivex":[]},"tags":{},"packages":[{"name":"hivex","source":"https://ubuntu.com/security/cve?package=hivex","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hivex","debian":"https://tracker.debian.org/pkg/hivex","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.3.11-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9270","published":"2014-12-08T16:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the\nprojax_array_serialize_for_autocomplete function in core/projax_api.php in\nMantisBT 1.1.0a3 through 1.2.17 allows remote attackers to inject arbitrary\nweb script or HTML via the \"profile/Platform\" field.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://github.com/mantisbt/mantisbt/commit/0bff06ec","http://www.mantisbt.org/bugs/view.php?id=17583","https://www.cve.org/CVERecord?id=CVE-2014-9270"],"bugs":[""],"patches":{"mantis":[]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9219","published":"2014-12-08T11:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the redirection feature in\nurl.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to\ninject arbitrary web script or HTML via the url parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/phpmyadmin/phpmyadmin/commit/9b2479b7216dd91a6cc2f231c0fd6b85d457f6e2","http://www.phpmyadmin.net/home_page/security/PMASA-2014-18.php","https://www.cve.org/CVERecord?id=CVE-2014-9219"],"bugs":[""],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"artful","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9218","published":"2014-12-08T11:59:00","updated_at":"2025-05-26T12:49:45.097875+00:00","description":"\nlibraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before\n4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a\ndenial of service (resource consumption) via a long password.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/phpmyadmin/phpmyadmin/commit/1ac863c7573d12012374d5d41e5c7dc5505ea6e1 (master)","http://www.phpmyadmin.net/home_page/security/PMASA-2014-17.php","https://www.cve.org/CVERecord?id=CVE-2014-9218","https://ubuntu.com/security/notices/USN-4843-1"],"bugs":[""],"patches":{"phpmyadmin":[]},"tags":{},"packages":[{"name":"phpmyadmin","source":"https://ubuntu.com/security/cve?package=phpmyadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpmyadmin","debian":"https://tracker.debian.org/pkg/phpmyadmin","statuses":[{"release_codename":"vivid","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4:4.0.10-1ubuntu0.1+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4:4.2.12-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4843-1"],"notices":[{"id":"USN-4843-1","title":"phpMyAdmin vulnerabilities","summary":"Several security issues were fixed in phpMyAdmin.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-16T14:27:57.040177","description":"Javier Nieto and Andres Rojas discovered that phpMyAdmin incorrectly\nmanaged input in the form of passwords. An attacker could use this\nvulnerability to cause a denial-of-service (DoS). This issue only\naffected Ubuntu 14.04 ESM. (CVE-2014-9218)\n\nEmanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize\ninput in the form of database names in the PHP Array export feature.\nAn authenticated attacker could use this vulnerability to run arbitrary\nPHP commands. This issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.\n(CVE-2016-6609)\n\nEmanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize\ninput. An attacker could use this vulnerability to execute SQL injection\nattacks. This issue only affected Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.\n(CVE-2016-6619)\n\nEmanuel Bronshtein discovered that phpMyadmin failed to properly sanitize\ninput. An authenticated attacker could use this vulnerability to cause a\ndenial-of-service (DoS). This issue only affected Ubuntu 14.04 ESM and\nUbuntu 16.04 ESM. (CVE-2016-6630)\n\nEmanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize\ninput. An attacker could use this vulnerability to bypass AllowRoot\nrestrictions and deny rules for usernames. This issue only affected Ubuntu\n14.04 ESM and Ubuntu 16.04 ESM. (CVE-2016-9849)\n\nEmanuel Bronshtein discovered that phpMyAdmin would allow sensitive\ninformation to be leaked when the argument separator in a URL was\nnot the default & value. An attacker could use this vulnerability to\nobtain the CSRF token of a user. This issue only affected Ubuntu\n14.04 ESM and Ubuntu 16.04 ESM. (CVE-2016-9866)\n\nIsaac Bennetch discovered that phpMyAdmin was incorrectly restricting\nuser access due to the behavior of the substr function on some PHP\nversions. An attacker could use this vulnerability to bypass login\nrestrictions established for users that have no password set. This\nissue only affected Ubuntu 14.04 ESM. This issue only affected Ubuntu\n14.04 ESM and Ubuntu 16.04 ESM. (CVE-2017-18264)\n\nEmanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize\ninput in the form of parameters sent during a table editing operation. An\nattacker could use this vulnerability to trigger an endless recursion\nand cause a denial-of-service (DoS). This issue only affected Ubuntu 14.04\nESM and Ubuntu 16.04 ESM. (CVE-2017-1000014)\n\nEmanuel Bronshtein discovered that phpMyAdmin failed to properly sanitize\ninput used to generate a web page. An authenticated attacker could use this\nvulnerability to execute CSS injection attacks. This issue only affected\nUbuntu 14.04 ESM and Ubuntu 16.04 ESM. (CVE-2017-1000015)\n\nIt was discovered that phpMyAdmin incorrectly handled certain input. An\nattacker could use this vulnerability to execute a cross-site scripting (XSS)\nattack via a crafted URL. This issue only affected Ubuntu 16.04 ESM.\n(CVE-2018-7260)\n\nIt was discovered phpMyAdmin incorrectly handled database names. An\nattacker could possibly use this to trigger a cross-site scripting\nattack. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM.\n(CVE-2018-12581)\n\nDaniel Le Gall discovered that phpMyAdmin would expose sensitive\ninformation to unauthorized actors due to an error in its transformation\nfeature. An authenticated attacker could use this vulnerability to leak\nthe contents of a local file. This issue only affected Ubuntu 14.04 ESM\nand Ubuntu 16.04 ESM. (CVE-2018-19968)\n\nIt was discovered that phpMyAdmin incorrectly handled user input. An\nattacker could possibly use this to perform a cross-site scripting attack.\nThis issue only affected Ubuntu 16.04 ESM. (CVE-2018-19970)\n\nIt was discovered that phpMyAdmin failed to properly sanitize input. An\nattacker could use this vulnerability to execute an SQL injection attack\nvia a specially crafted database name. This issue only affected Ubuntu\n16.04 ESM. (CVE-2019-11768)\n\nIt was discovered that phpMyAdmin incorrectly handled some requests. An\nattacker could possibly use this to perform a cross site request forgery\nattack. This issue only affected Ubuntu 16.04 ESM. (CVE-2019-12616)\n\nIt was discovered that phpMyAdmin incorrectly handled some requests. An\nattacker could possibly use this to perform a cross site request forgery\nattack. This issue only affected Ubuntu 14.04 ESM and Ubuntu 18.04 ESM.\n(CVE-2019-12922)\n\nIt was discovered that phpMyAdmin failed to properly sanitize input. An\nattacker could use this vulnerability to execute an SQL injection attack\nvia a specially crafted username. This issue only affected Ubuntu 16.04 ESM.\n(CVE-2019-6798)\n\nIt was discovered that phpMyAdmin did not properly sanitize certain input.\nAn attacker could use this vulnerability to possibly execute an HTML injection\nor a cross-site scripting (XSS) attack. This issue only affected Ubuntu 14.04\nESM and Ubuntu 16.04 ESM. (CVE-2019-19617)\n\nCSW Research Labs discovered that phpMyAdmin failed to properly sanitize\ninput. An attacker could use this vulnerability to execute SQL injection\nattacks. This issue only affected Ubuntu 16.04 ESM. (CVE-2020-5504)\n\nGiwan Go and Yelang Lee discovered that phpMyAdmin was vulnerable to an\nXSS attack in the transformation feature. If a victim were to click on a\ncrafted link, an attacker could run malicious JavaScript on the victim's\nsystem. This issue was only fixed in Ubuntu 20.04 ESM. (CVE-2020-26934)\n\nAndre Sá discovered that phpMyAdmin incorrectly handled certain SQL\nstatements in the search feature. A remote, authenticated attacker could\nuse this to inject malicious SQL into a query. This issue only affected\nUbuntu 20.04 ESM. (CVE-2020-26935)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"phpmyadmin","version":"4:4.0.10-1ubuntu0.1+esm4","description":"MySQL web administration tool","is_source":true},{"name":"phpmyadmin","version":"4:4.0.10-1ubuntu0.1+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/phpmyadmin","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"phpmyadmin","version":"4:4.5.4.1-2ubuntu2.1+esm6","description":"MySQL web administration tool","is_source":true},{"name":"phpmyadmin","version":"4:4.5.4.1-2ubuntu2.1+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/phpmyadmin","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"phpmyadmin","version":"4:4.6.6-5ubuntu0.5+esm1","description":"MySQL web administration tool","is_source":true},{"name":"phpmyadmin","version":"4:4.6.6-5ubuntu0.5+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/phpmyadmin","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"phpmyadmin","version":"4:4.9.5+dfsg1-2ubuntu0.1~esm1","description":"MySQL web administration tool","is_source":true},{"name":"phpmyadmin","version":"4:4.9.5+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/phpmyadmin","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-12922","CVE-2016-6619","CVE-2020-26934","CVE-2019-19617","CVE-2016-9866","CVE-2018-19968","CVE-2018-7260","CVE-2019-11768","CVE-2018-19970","CVE-2019-6798","CVE-2017-1000014","CVE-2017-1000015","CVE-2020-5504","CVE-2018-12581","CVE-2016-6630","CVE-2016-9849","CVE-2020-26935","CVE-2019-12616","CVE-2016-6609","CVE-2014-9218","CVE-2017-18264"]}]},{"id":"CVE-2014-9130","published":"2014-12-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nscanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka\nYAML-XS) module for Perl, allows context-dependent attackers to cause a\ndenial of service (assertion failure and crash) via vectors involving\nline-wrapping.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"pyyaml may receive its own CVE"},{"author":"mdeslaur","note":"perl PoC: http://www.openwall.com/lists/oss-security/2014/11/28/6"},{"author":"sbeattie","note":"ruby1.9+ uses libyaml-0-2, so it's fixed when libyaml is fixed"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/11/28/8","https://ubuntu.com/security/notices/USN-2461-1","https://ubuntu.com/security/notices/USN-2461-2","https://ubuntu.com/security/notices/USN-2461-3","https://www.cve.org/CVERecord?id=CVE-2014-9130"],"bugs":["https://bitbucket.org/xi/libyaml/issue/10/wrapped-strings-cause-assert-failure","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771365 (libyaml-libyaml-perl)","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771366 (libyaml)","https://bugs.launchpad.net/ubuntu/+source/libyaml/+bug/1400736"],"patches":{"libyaml":["upstream: https://bitbucket.org/xi/libyaml/commits/2b9156756423e967cfd09a61d125d883fca6f4f2"],"libyaml-libyaml-perl":[],"pyyaml":["upstream: https://bitbucket.org/xi/pyyaml/commits/ddf211a41bb231c365fece5599b7e484e6dc33fc"]},"tags":{},"packages":[{"name":"libyaml","source":"https://ubuntu.com/security/cve?package=libyaml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libyaml","debian":"https://tracker.debian.org/pkg/libyaml","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.1.6-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.1.4-2ubuntu0.12.04.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.1.4-3ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"0.1.6-1ubuntu0.1","component":null,"pocket":"security"}]},{"name":"libyaml-libyaml-perl","source":"https://ubuntu.com/security/cve?package=libyaml-libyaml-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libyaml-libyaml-perl","debian":"https://tracker.debian.org/pkg/libyaml-libyaml-perl","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.38-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.41-5ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.41-6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"0.41-5ubuntu0.14.10.1","component":null,"pocket":"security"}]},{"name":"pyyaml","source":"https://ubuntu.com/security/cve?package=pyyaml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pyyaml","debian":"https://tracker.debian.org/pkg/pyyaml","statuses":[{"release_codename":"utopic","status":"released","description":"3.11-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.10-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.10-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2461-1","USN-2461-3","USN-2461-2"],"notices":[{"id":"USN-2461-1","title":"LibYAML vulnerability","summary":"Applications using LibYAML could be made to crash if they received\nspecially crafted input.\n","instructions":"After a standard system update you need to restart applications using\nLibYAML to make all the necessary changes.\n","references":[],"published":"2015-01-12T22:24:49.275120","description":"Stanisław Pitucha and Jonathan Gray discovered that LibYAML did not\nproperly handle wrapped strings. An attacker could create specially\ncrafted YAML data to trigger an assert, causing a denial of service.\n","is_hidden":false,"release_packages":{"precise":[{"name":"libyaml","version":"0.1.4-2ubuntu0.12.04.4","description":"Fast YAML 1.1 parser and emitter library","is_source":true},{"name":"libyaml-0-2","version":"0.1.4-2ubuntu0.12.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libyaml","version_link":"https://launchpad.net/ubuntu/+source/libyaml/0.1.4-2ubuntu0.12.04.4"}],"trusty":[{"name":"libyaml","version":"0.1.4-3ubuntu3.1","description":"Fast YAML 1.1 parser and emitter library","is_source":true},{"name":"libyaml-0-2","version":"0.1.4-3ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libyaml","version_link":"https://launchpad.net/ubuntu/+source/libyaml/0.1.4-3ubuntu3.1","pocket":"security"},{"name":"libyaml-dev","version":"0.1.4-3ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libyaml","version_link":"https://launchpad.net/ubuntu/+source/libyaml/0.1.4-3ubuntu3.1","pocket":"security"}],"utopic":[{"name":"libyaml","version":"0.1.6-1ubuntu0.1","description":"Fast YAML 1.1 parser and emitter library","is_source":true},{"name":"libyaml-0-2","version":"0.1.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libyaml","version_link":"https://launchpad.net/ubuntu/+source/libyaml/0.1.6-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2014-9130"]},{"id":"USN-2461-3","title":"PyYAML vulnerability","summary":"Applications using PyYAML could be made to crash if they received\nspecially crafted input.\n","instructions":"After a standard system update you need to restart applications using\nPyYAML to make all the necessary changes.\n","references":[],"published":"2015-01-12T22:12:40.332183","description":"Stanisław Pitucha and Jonathan Gray discovered that PyYAML did not\nproperly handle wrapped strings. An attacker could create specially\ncrafted YAML data to trigger an assert, causing a denial of service.\n","is_hidden":false,"release_packages":{"precise":[{"name":"pyyaml","version":"3.10-2ubuntu0.1","description":"YAML parser and emitter for Python","is_source":true},{"name":"python-yaml","version":"3.10-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyyaml","version_link":"https://launchpad.net/ubuntu/+source/pyyaml/3.10-2ubuntu0.1"},{"name":"python3-yaml","version":"3.10-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyyaml","version_link":"https://launchpad.net/ubuntu/+source/pyyaml/3.10-2ubuntu0.1"}],"trusty":[{"name":"pyyaml","version":"3.10-4ubuntu0.1","description":"YAML parser and emitter for Python","is_source":true},{"name":"python-yaml","version":"3.10-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyyaml","version_link":"https://launchpad.net/ubuntu/+source/pyyaml/3.10-4ubuntu0.1","pocket":"security"},{"name":"python3-yaml","version":"3.10-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyyaml","version_link":"https://launchpad.net/ubuntu/+source/pyyaml/3.10-4ubuntu0.1","pocket":"security"}],"utopic":[{"name":"pyyaml","version":"3.11-1ubuntu0.1","description":"YAML parser and emitter for Python","is_source":true},{"name":"python-yaml","version":"3.11-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyyaml","version_link":"https://launchpad.net/ubuntu/+source/pyyaml/3.11-1ubuntu0.1"},{"name":"python3-yaml","version":"3.11-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pyyaml","version_link":"https://launchpad.net/ubuntu/+source/pyyaml/3.11-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2014-9130"]},{"id":"USN-2461-2","title":"libyaml-libyaml-perl vulnerability","summary":"Applications using libyaml-libyaml-perl could be made to crash if\nthey received specially crafted input.\n","instructions":"After a standard system update you need to restart applications using\nlibyaml-libyaml-perl to make all the necessary changes.\n","references":[],"published":"2015-01-12T22:25:45.242500","description":"Stanisław Pitucha and Jonathan Gray discovered that\nlibyaml-libyaml-perl did not properly handle wrapped strings. An\nattacker could create specially crafted YAML data to trigger an assert,\ncausing a denial of service.\n","is_hidden":false,"release_packages":{"precise":[{"name":"libyaml-libyaml-perl","version":"0.38-2ubuntu0.2","description":"Perl interface to libyaml, a YAML implementation","is_source":true},{"name":"libyaml-libyaml-perl","version":"0.38-2ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl","version_link":"https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl/0.38-2ubuntu0.2"}],"trusty":[{"name":"libyaml-libyaml-perl","version":"0.41-5ubuntu0.14.04.1","description":"Perl interface to libyaml, a YAML implementation","is_source":true},{"name":"libyaml-libyaml-perl","version":"0.41-5ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl","version_link":"https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl/0.41-5ubuntu0.14.04.1","pocket":"security"}],"utopic":[{"name":"libyaml-libyaml-perl","version":"0.41-5ubuntu0.14.10.1","description":"Perl interface to libyaml, a YAML implementation","is_source":true},{"name":"libyaml-libyaml-perl","version":"0.41-5ubuntu0.14.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl","version_link":"https://launchpad.net/ubuntu/+source/libyaml-libyaml-perl/0.41-5ubuntu0.14.10.1"}]},"type":"USN","cves_ids":["CVE-2014-9130"]}]},{"id":"CVE-2014-8134","published":"2014-12-08T00:00:00","updated_at":"2026-07-04T07:38:53.654067+00:00","description":"\nThe paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux\nkernel through 3.18 uses an improper paravirt_enabled setting for KVM guest\nkernels, which makes it easier for guest OS users to bypass the ASLR\nprotection mechanism via a crafted application that reads a 16-bit value.","ubuntu_description":"\nAn information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel.","notes":[{"author":"jdstrand","note":"android kernels (flo, goldfish, grouper, maguro, mako and manta) are\nnot supported on the Ubuntu Touch 14.04 preview kernels\nlinux-lts-saucy no longer receives official support\nlinux-lts-quantal no longer receives official support"}],"codename":null,"priority":"high","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2441-1","https://ubuntu.com/security/notices/USN-2442-1","https://ubuntu.com/security/notices/USN-2443-1","https://ubuntu.com/security/notices/USN-2444-1","https://ubuntu.com/security/notices/USN-2445-1","https://ubuntu.com/security/notices/USN-2446-1","https://ubuntu.com/security/notices/USN-2447-1","https://ubuntu.com/security/notices/USN-2448-1","https://ubuntu.com/security/notices/USN-2464-1","https://www.cve.org/CVERecord?id=CVE-2014-8134"],"bugs":["https://launchpad.net/bugs/1400314"],"patches":{"linux":["break-fix: 6aa8b732ca01c3d7a54e93f4d701b8aabbe60fb7 29fa6825463c97e5157284db80107d1bfac5d77b"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-70.137","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-74.109","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-43.72","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"3.16.0-28.37","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-28.38","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1642.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-374.91","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.13.0-43.72~precise1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.16.0-28.37~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1458.78","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.19~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2442-1","USN-2445-1","USN-2464-1","USN-2447-1","USN-2443-1","USN-2448-1","USN-2446-1","USN-2441-1"],"notices":[{"id":"USN-2442-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-12-12T07:32:55.169117","description":"An information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nA flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(system crash). (CVE-2014-3673)\n\nA flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(panic). (CVE-2014-3687)\n\nIt was discovered that excessive queuing by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel can cause memory\npressure. A remote attacker could exploit this flaw to cause a denial of\nservice. (CVE-2014-3688)\n\nA null pointer dereference flaw was discovered in the the Linux kernel's\nSCTP implementation when ASCONF is used. A remote attacker could exploit\nthis flaw to cause a denial of service (system crash) via a malformed INIT\nchunk. (CVE-2014-7841)\n\nJouni Malinen reported a flaw in the handling of fragmentation in the\nmac8Linux subsystem of the kernel. A remote attacker could exploit this\nflaw to obtain potential sensitive cleartext information by reading\npackets. (CVE-2014-8709)\n\nA stack buffer overflow was discovered in the ioctl command handling for\nthe Technotrend/Hauppauge USB DEC devices driver. A local user could\nexploit this flaw to cause a denial of service (system crash) or possibly\ngain privileges. (CVE-2014-8884)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-374.91","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-374-ec2","version":"2.6.32-374.91","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-374.91"}]},"type":"USN","cves_ids":["CVE-2014-3673","CVE-2014-3687","CVE-2014-3688","CVE-2014-7841","CVE-2014-8134","CVE-2014-8709","CVE-2014-8884","CVE-2014-9090"]},{"id":"USN-2445-1","title":"Linux kernel (Trusty HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-12-12T07:40:55.639121","description":"\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register in the x86\narchitecture. A local attacker could exploit this flaw to gain\nadministrative privileges. (CVE-2014-9322)\n\nAn information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nRabin Vincent, Robert Swiecki, Russell King discovered that the ftrace\nsubsystem of the Linux kernel does not properly handle private syscall\nnumbers. A local user could exploit this flaw to cause a denial of service\n(OOPS). (CVE-2014-7826)\n\nA flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(system crash). (CVE-2014-3673)\n\nA flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(panic). (CVE-2014-3687)\n\nIt was discovered that excessive queuing by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel can cause memory\npressure. A remote attacker could exploit this flaw to cause a denial of\nservice. (CVE-2014-3688)\n\nRabin Vincent, Robert Swiecki, Russell Kinglaw discovered a flaw in how the\nperf subsystem of the Linux kernel handles private systecall numbers. A\nlocal user could exploit this to cause a denial of service (OOPS) or bypass\nASLR protections via a crafted application. (CVE-2014-7825)\n\nThe KVM (kernel virtual machine) subsystem of the Linux kernel\nmiscalculates the number of memory pages during the handling of a mapping\nfailure. A guest OS user could exploit this to cause a denial of service\n(host OS page unpinning) or possibly have unspecified other impact by\nleveraging guest OS privileges. (CVE-2014-8369)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-43.72~precise1","description":"Linux hardware enablement kernel from Trusty","is_source":true},{"name":"linux-image-3.13.0-43-generic","version":"3.13.0-43.72~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-43.72~precise1"},{"name":"linux-image-3.13.0-43-generic-lpae","version":"3.13.0-43.72~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-43.72~precise1"}]},"type":"USN","cves_ids":["CVE-2014-3673","CVE-2014-3687","CVE-2014-3688","CVE-2014-7825","CVE-2014-7826","CVE-2014-8134","CVE-2014-8369","CVE-2014-9090","CVE-2014-9322"]},{"id":"USN-2464-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2015-01-13T11:40:29.440252","description":"\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register in the x86\narchitecture. A local attacker could exploit this flaw to gain\nadministrative privileges. (CVE-2014-9322)\n\nAn information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nA race condition with MMIO and PIO transactions in the KVM (Kernel Virtual\nMachine) subsystem of the Linux kernel was discovered. A guest OS user\ncould exploit this flaw to cause a denial of service (guest OS crash) via a\nspecially crafted application. (CVE-2014-7842)\n\nThe KVM (kernel virtual machine) subsystem of the Linux kernel\nmiscalculates the number of memory pages during the handling of a mapping\nfailure. A guest OS user could exploit this to cause a denial of service\n(host OS page unpinning) or possibly have unspecified other impact by\nleveraging guest OS privileges. (CVE-2014-8369)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-ti-omap4","version":"3.2.0-1458.78","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.2.0-1458-omap4","version":"3.2.0-1458.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1458.78"}]},"type":"USN","cves_ids":["CVE-2014-7842","CVE-2014-8134","CVE-2014-8369","CVE-2014-9090","CVE-2014-9322"]},{"id":"USN-2447-1","title":"Linux kernel (Utopic HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-12-12T07:47:06.518716","description":"\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register in the x86\narchitecture. A local attacker could exploit this flaw to gain\nadministrative privileges. (CVE-2014-9322)\n\nAn information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nRabin Vincent, Robert Swiecki, Russell King discovered that the ftrace\nsubsystem of the Linux kernel does not properly handle private syscall\nnumbers. A local user could exploit this flaw to cause a denial of service\n(OOPS). (CVE-2014-7826)\n\nA flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(system crash). (CVE-2014-3673)\n\nA flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(panic). (CVE-2014-3687)\n\nIt was discovered that excessive queuing by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel can cause memory\npressure. A remote attacker could exploit this flaw to cause a denial of\nservice. (CVE-2014-3688)\n\nRabin Vincent, Robert Swiecki, Russell Kinglaw discovered a flaw in how the\nperf subsystem of the Linux kernel handles private systecall numbers. A\nlocal user could exploit this to cause a denial of service (OOPS) or bypass\nASLR protections via a crafted application. (CVE-2014-7825)\n\nAndy Lutomirski discovered a flaw in how the Linux kernel handles\npivot_root when used with a chroot directory. A local user could exploit\nthis flaw to cause a denial of service (mount-tree loop). (CVE-2014-7970)\n\nDmitry Monakhov discovered a race condition in the ext4_file_write_iter\nfunction of the Linux kernel's ext4 filesystem. A local user could exploit\nthis flaw to cause a denial of service (file unavailability).\n(CVE-2014-8086)\n\nThe KVM (kernel virtual machine) subsystem of the Linux kernel\nmiscalculates the number of memory pages during the handling of a mapping\nfailure. A guest OS user could exploit this to cause a denial of service\n(host OS page unpinning) or possibly have unspecified other impact by\nleveraging guest OS privileges. (CVE-2014-8369)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-utopic","version":"3.16.0-28.37~14.04.1","description":"Linux hardware enablement kernel from Utopic","is_source":true},{"name":"linux-image-3.16.0-28-generic","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-28-generic-lpae","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-28-lowlatency","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-28-powerpc-e500mc","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-28-powerpc-smp","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-28-powerpc64-emb","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"},{"name":"linux-image-3.16.0-28-powerpc64-smp","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"},{"name":"linux-image-extra-3.16.0-28-generic","version":"3.16.0-28.37~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-utopic/3.16.0-28.37~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3673","CVE-2014-3687","CVE-2014-3688","CVE-2014-7825","CVE-2014-7826","CVE-2014-7970","CVE-2014-8086","CVE-2014-8134","CVE-2014-8369","CVE-2014-9090","CVE-2014-9322"]},{"id":"USN-2443-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-12-12T07:35:36.327217","description":"\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register in the x86\narchitecture. A local attacker could exploit this flaw to gain\nadministrative privileges. (CVE-2014-9322)\n\nAn information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nRabin Vincent, Robert Swiecki, Russell King discovered that the ftrace\nsubsystem of the Linux kernel does not properly handle private syscall\nnumbers. A local user could exploit this flaw to cause a denial of service\n(OOPS). (CVE-2014-7826)\n\nRabin Vincent, Robert Swiecki, Russell Kinglaw discovered a flaw in how the\nperf subsystem of the Linux kernel handles private systecall numbers. A\nlocal user could exploit this to cause a denial of service (OOPS) or bypass\nASLR protections via a crafted application. (CVE-2014-7825)\n\nA null pointer dereference flaw was discovered in the the Linux kernel's\nSCTP implementation when ASCONF is used. A remote attacker could exploit\nthis flaw to cause a denial of service (system crash) via a malformed INIT\nchunk. (CVE-2014-7841)\n\nA stack buffer overflow was discovered in the ioctl command handling for\nthe Technotrend/Hauppauge USB DEC devices driver. A local user could\nexploit this flaw to cause a denial of service (system crash) or possibly\ngain privileges. (CVE-2014-8884)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux","version":"3.2.0-74.109","description":"Linux kernel","is_source":true},{"name":"linux-image-3.2.0-74-highbank","version":"3.2.0-74.109","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-74.109"},{"name":"linux-image-3.2.0-74-generic-pae","version":"3.2.0-74.109","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-74.109"},{"name":"linux-image-3.2.0-74-powerpc64-smp","version":"3.2.0-74.109","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-74.109"},{"name":"linux-image-3.2.0-74-omap","version":"3.2.0-74.109","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-74.109"},{"name":"linux-image-3.2.0-74-generic","version":"3.2.0-74.109","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-74.109"},{"name":"linux-image-3.2.0-74-powerpc-smp","version":"3.2.0-74.109","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-74.109"},{"name":"linux-image-3.2.0-74-virtual","version":"3.2.0-74.109","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-74.109"}]},"type":"USN","cves_ids":["CVE-2014-7825","CVE-2014-7826","CVE-2014-7841","CVE-2014-8134","CVE-2014-8884","CVE-2014-9090","CVE-2014-9322"]},{"id":"USN-2448-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-12-12T07:49:36.287676","description":"\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register in the x86\narchitecture. A local attacker could exploit this flaw to gain\nadministrative privileges. (CVE-2014-9322)\n\nAn information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nRabin Vincent, Robert Swiecki, Russell King discovered that the ftrace\nsubsystem of the Linux kernel does not properly handle private syscall\nnumbers. A local user could exploit this flaw to cause a denial of service\n(OOPS). (CVE-2014-7826)\n\nA flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(system crash). (CVE-2014-3673)\n\nA flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(panic). (CVE-2014-3687)\n\nIt was discovered that excessive queuing by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel can cause memory\npressure. A remote attacker could exploit this flaw to cause a denial of\nservice. (CVE-2014-3688)\n\nRabin Vincent, Robert Swiecki, Russell Kinglaw discovered a flaw in how the\nperf subsystem of the Linux kernel handles private systecall numbers. A\nlocal user could exploit this to cause a denial of service (OOPS) or bypass\nASLR protections via a crafted application. (CVE-2014-7825)\n\nAndy Lutomirski discovered a flaw in how the Linux kernel handles\npivot_root when used with a chroot directory. A local user could exploit\nthis flaw to cause a denial of service (mount-tree loop). (CVE-2014-7970)\n\nDmitry Monakhov discovered a race condition in the ext4_file_write_iter\nfunction of the Linux kernel's ext4 filesystem. A local user could exploit\nthis flaw to cause a denial of service (file unavailability).\n(CVE-2014-8086)\n\nThe KVM (kernel virtual machine) subsystem of the Linux kernel\nmiscalculates the number of memory pages during the handling of a mapping\nfailure. A guest OS user could exploit this to cause a denial of service\n(host OS page unpinning) or possibly have unspecified other impact by\nleveraging guest OS privileges. (CVE-2014-8369)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"utopic":[{"name":"linux","version":"3.16.0-28.37","description":"Linux kernel","is_source":true},{"name":"linux-image-3.16.0-28-lowlatency","version":"3.16.0-28.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.16.0-28.37"},{"name":"linux-image-3.16.0-28-powerpc64-emb","version":"3.16.0-28.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.16.0-28.37"},{"name":"linux-image-3.16.0-28-generic","version":"3.16.0-28.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.16.0-28.37"},{"name":"linux-image-3.16.0-28-powerpc-e500mc","version":"3.16.0-28.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.16.0-28.37"},{"name":"linux-image-3.16.0-28-powerpc64-smp","version":"3.16.0-28.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.16.0-28.37"},{"name":"linux-image-3.16.0-28-generic-lpae","version":"3.16.0-28.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.16.0-28.37"},{"name":"linux-image-3.16.0-28-powerpc-smp","version":"3.16.0-28.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.16.0-28.37"}]},"type":"USN","cves_ids":["CVE-2014-3673","CVE-2014-3687","CVE-2014-3688","CVE-2014-7825","CVE-2014-7826","CVE-2014-7970","CVE-2014-8086","CVE-2014-8134","CVE-2014-8369","CVE-2014-9090","CVE-2014-9322"]},{"id":"USN-2446-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-12-12T07:43:36.552192","description":"\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register in the x86\narchitecture. A local attacker could exploit this flaw to gain\nadministrative privileges. (CVE-2014-9322)\n\nAn information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nRabin Vincent, Robert Swiecki, Russell King discovered that the ftrace\nsubsystem of the Linux kernel does not properly handle private syscall\nnumbers. A local user could exploit this flaw to cause a denial of service\n(OOPS). (CVE-2014-7826)\n\nA flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(system crash). (CVE-2014-3673)\n\nA flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(panic). (CVE-2014-3687)\n\nIt was discovered that excessive queuing by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel can cause memory\npressure. A remote attacker could exploit this flaw to cause a denial of\nservice. (CVE-2014-3688)\n\nRabin Vincent, Robert Swiecki, Russell Kinglaw discovered a flaw in how the\nperf subsystem of the Linux kernel handles private systecall numbers. A\nlocal user could exploit this to cause a denial of service (OOPS) or bypass\nASLR protections via a crafted application. (CVE-2014-7825)\n\nThe KVM (kernel virtual machine) subsystem of the Linux kernel\nmiscalculates the number of memory pages during the handling of a mapping\nfailure. A guest OS user could exploit this to cause a denial of service\n(host OS page unpinning) or possibly have unspecified other impact by\nleveraging guest OS privileges. (CVE-2014-8369)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-43.72","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-43-generic","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-3.13.0-43-generic-lpae","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-3.13.0-43-lowlatency","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-3.13.0-43-powerpc-e500","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-3.13.0-43-powerpc-e500mc","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-3.13.0-43-powerpc-smp","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-3.13.0-43-powerpc64-emb","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-3.13.0-43-powerpc64-smp","version":"3.13.0-43.72","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"},{"name":"linux-image-extra-3.13.0-43-generic","version":"3.13.0-43.72","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-43.72","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3673","CVE-2014-3687","CVE-2014-3688","CVE-2014-7825","CVE-2014-7826","CVE-2014-8134","CVE-2014-8369","CVE-2014-9090","CVE-2014-9322"]},{"id":"USN-2441-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-12-12T07:29:02.481383","description":"An information leak in the Linux kernel was discovered that could leak the\nhigh 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine\n(KVM) paravirt guests. A user in the guest OS could exploit this leak to\nobtain information that could potentially be used to aid in attacking the\nkernel. (CVE-2014-8134)\n\nA flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(system crash). (CVE-2014-3673)\n\nA flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel was discovered. A\nremote attacker could exploit this flaw to cause a denial of service\n(panic). (CVE-2014-3687)\n\nIt was discovered that excessive queuing by SCTP (Stream Control\nTransmission Protocol) implementation in the Linux kernel can cause memory\npressure. A remote attacker could exploit this flaw to cause a denial of\nservice. (CVE-2014-3688)\n\nA null pointer dereference flaw was discovered in the the Linux kernel's\nSCTP implementation when ASCONF is used. A remote attacker could exploit\nthis flaw to cause a denial of service (system crash) via a malformed INIT\nchunk. (CVE-2014-7841)\n\nJouni Malinen reported a flaw in the handling of fragmentation in the\nmac8Linux subsystem of the kernel. A remote attacker could exploit this\nflaw to obtain potential sensitive cleartext information by reading\npackets. (CVE-2014-8709)\n\nA stack buffer overflow was discovered in the ioctl command handling for\nthe Technotrend/Hauppauge USB DEC devices driver. A local user could\nexploit this flaw to cause a denial of service (system crash) or possibly\ngain privileges. (CVE-2014-8884)\n\nAndy Lutomirski discovered that the Linux kernel does not properly handle\nfaults associated with the Stack Segment (SS) register on the x86\narchitecture. A local attacker could exploit this flaw to cause a denial of\nservice (panic). (CVE-2014-9090)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-70.137","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-70-generic-pae","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-virtual","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-lpia","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-sparc64","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-server","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-powerpc-smp","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-versatile","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-powerpc64-smp","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-386","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-generic","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-powerpc","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-sparc64-smp","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-preempt","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"},{"name":"linux-image-2.6.32-70-ia64","version":"2.6.32-70.137","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-70.137"}]},"type":"USN","cves_ids":["CVE-2014-3673","CVE-2014-3687","CVE-2014-3688","CVE-2014-7841","CVE-2014-8134","CVE-2014-8709","CVE-2014-8884","CVE-2014-9090"]}]},{"id":"CVE-2014-8106","published":"2014-12-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the Cirrus VGA emulator\n(hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to\nexecute arbitrary code via vectors related to blit regions. NOTE: this\nvulnerability exists because an incomplete fix for CVE-2007-1320.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://lists.nongnu.org/archive/html/qemu-devel/2014-12/msg00508.html","https://ubuntu.com/security/notices/USN-2439-1","https://www.cve.org/CVERecord?id=CVE-2014-8106"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=772025","https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1400775"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=d3532a0db02296e687711b8cdc7791924efccea0","upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=bf25983345ca44aec3dd92c57142be45452bd38a"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2.1+dfsg-4ubuntu6.3","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"lucid","status":"released","description":"0.12.3+noroms-0ubuntu9.26","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.21","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2439-1"],"notices":[{"id":"USN-2439-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-12-11T19:10:58.669891","description":"Michael S. Tsirkin discovered that QEMU incorrectly handled certain\nparameters during ram load while performing a migration. An attacker able\nto manipulate savevm data could use this issue to possibly execute\narbitrary code on the host. This issue only affected Ubuntu 12.04 LTS,\nUbuntu 14.04 LTS, and Ubuntu 14.10. (CVE-2014-7840)\n\nPaolo Bonzini discovered that QEMU incorrectly handled memory in the Cirrus\nVGA device. A malicious guest could possibly use this issue to write into\nmemory of the host, leading to privilege escalation. (CVE-2014-8106)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.26","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/0.12.3+noroms-0ubuntu9.26"}],"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.21","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.21"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.9","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.9","pocket":"security"}],"utopic":[{"name":"qemu","version":"2.1+dfsg-4ubuntu6.3","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"},{"name":"qemu-system-aarch64","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"},{"name":"qemu-system-arm","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"},{"name":"qemu-system-mips","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"},{"name":"qemu-system-misc","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"},{"name":"qemu-system-ppc","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"},{"name":"qemu-system-sparc","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"},{"name":"qemu-system-x86","version":"2.1+dfsg-4ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.1+dfsg-4ubuntu6.3"}]},"type":"USN","cves_ids":["CVE-2014-7840","CVE-2014-8106"]}]},{"id":"CVE-2014-1693","published":"2014-12-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP\nR15B03 allow context-dependent attackers to inject arbitrary FTP commands\nvia CRLF sequences in the (1) user, (2) account, (3) cd, (4) ls, (5) nlist,\n(6) rename, (7) delete, (8) mkdir, (9) rmdir, (10) recv, (11) recv_bin,\n(12) recv_chunk_start, (13) send, (14) send_bin, (15) send_chunk_start,\n(16) append_chunk_start, (17) append, or (18) append_bin command.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"requires MITM between erlang system and ftp server or for the web\nserver to not do input sanitization"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/01/29/3","http://www.openwall.com/lists/oss-security/2014/01/29","http://erlang.org/pipermail/erlang-bugs/2014-January/003998.html","https://ubuntu.com/security/notices/USN-3571-1","https://www.cve.org/CVERecord?id=CVE-2014-1693"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=738132"],"patches":{"erlang":["upstream: https://github.com/erlang/otp/commit/6995e4764d2722ca315a68facd8777f3c8970db7"]},"tags":{},"packages":[{"name":"erlang","source":"https://ubuntu.com/security/cve?package=erlang","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=erlang","debian":"https://tracker.debian.org/pkg/erlang","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1:17.3-dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1:17.3-dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:16.b.3-dfsg-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:16.b.3.1-dfsg-3,1:15.b.1-dfsg-4+deb7u1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:17.1-dfsg-4ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:17.3-dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:17.3-dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1:17.3-dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:17.3-dfsg-3ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3571-1"],"notices":[{"id":"USN-3571-1","title":"Erlang vulnerabilities","summary":"Several security issues were fixed in Erlang.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2018-02-14T14:54:29.756770","description":"It was discovered that the Erlang FTP module incorrectly handled certain\nCRLF sequences. A remote attacker could possibly use this issue to inject\narbitrary FTP commands. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2014-1693)\n\nIt was discovered that Erlang incorrectly checked CBC padding bytes. A\nremote attacker could possibly use this issue to perform a padding oracle\nattack and decrypt traffic. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2015-2774)\n\nIt was discovered that Erlang incorrectly handled certain regular\nexpressions. A remote attacker could possibly use this issue to cause\nErlang to crash, resulting in a denial of service, or execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10253)\n\nHanno Böck, Juraj Somorovsky and Craig Young discovered that the Erlang\notp TLS server incorrectly handled error reporting. A remote attacker could\npossibly use this issue to perform a variation of the Bleichenbacher attack\nand decrypt traffic or sign messages. (CVE-2017-1000385)\n","is_hidden":false,"release_packages":{"artful":[{"name":"erlang","version":"1:20.0.4+dfsg-1ubuntu1.1","description":"Concurrent, real-time, distributed functional language","is_source":true},{"name":"erlang","version":"1:20.0.4+dfsg-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:20.0.4+dfsg-1ubuntu1.1"}],"trusty":[{"name":"erlang","version":"1:16.b.3-dfsg-1ubuntu2.2","description":"Concurrent, real-time, distributed functional language","is_source":true},{"name":"erlang","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-appmon","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-asn1","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-base","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-base-hipe","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-common-test","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-corba","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-crypto","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-debugger","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-dev","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-dialyzer","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-diameter","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-doc","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-edoc","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-eldap","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-erl-docgen","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-et","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-eunit","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-examples","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-gs","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ic","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ic-java","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-inets","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-jinterface","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-manpages","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-megaco","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-mnesia","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-mode","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-nox","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-observer","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-odbc","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-os-mon","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-parsetools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-percept","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-pman","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-public-key","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-reltool","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-runtime-tools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-snmp","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-src","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ssh","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-ssl","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-syntax-tools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-test-server","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-toolbar","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-tools","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-tv","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-typer","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-webtool","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-x11","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"},{"name":"erlang-xmerl","version":"1:16.b.3-dfsg-1ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:16.b.3-dfsg-1ubuntu2.2","pocket":"security"}],"xenial":[{"name":"erlang","version":"1:18.3-dfsg-1ubuntu3.1","description":"Concurrent, real-time, distributed functional language","is_source":true},{"name":"erlang","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-asn1","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-base","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-base-hipe","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-common-test","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-corba","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-crypto","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-debugger","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-dev","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-dialyzer","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-diameter","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-doc","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-edoc","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-eldap","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-erl-docgen","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-et","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-eunit","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-examples","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-gs","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ic","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ic-java","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-inets","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-jinterface","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-manpages","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-megaco","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-mnesia","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-mode","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-nox","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-observer","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-odbc","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-os-mon","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-parsetools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-percept","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-public-key","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-reltool","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-runtime-tools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-snmp","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-src","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ssh","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-ssl","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-syntax-tools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-test-server","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-tools","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-typer","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-webtool","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-wx","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-x11","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"},{"name":"erlang-xmerl","version":"1:18.3-dfsg-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/erlang","version_link":"https://launchpad.net/ubuntu/+source/erlang/1:18.3-dfsg-1ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-1693","CVE-2015-2774","CVE-2016-10253","CVE-2017-1000385"]}]},{"id":"CVE-2014-9117","published":"2014-12-06T21:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMantisBT before 1.2.18 uses the public_key parameter value as the key to\nthe CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA\nprotection mechanism by leveraging knowledge of a CAPTCHA answer for a\npublic_key parameter value, as demonstrated by E4652 for the public_key\nvalue 0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://github.com/mantisbt/mantisbt/commit/7bb78e4581ff1092c811ea96582fe602624cdcdd","https://www.mantisbt.org/bugs/view.php?id=17811","https://www.cve.org/CVERecord?id=CVE-2014-9117"],"bugs":[""],"patches":{"mantis":["upstream: http://github.com/mantisbt/mantisbt/commit/7bb78e4581ff1092c811ea96582fe602624cdcdd"]},"tags":{},"packages":[{"name":"mantis","source":"https://ubuntu.com/security/cve?package=mantis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mantis","debian":"https://tracker.debian.org/pkg/mantis","statuses":[{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-9278","published":"2014-12-06T15:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and\nwhen running in a Kerberos environment, allows remote authenticated users\nto log in as another user when they are listed in the .k5users file of that\nuser, which might bypass intended authentication requirements that would\nforce a local login.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"vulnerable patch not included in Debian/Ubuntu"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1169843","https://www.cve.org/CVERecord?id=CVE-2014-9278"],"bugs":[""],"patches":{"openssh":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-8990","published":"2014-12-05T16:59:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ndefault-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to\nexecute arbitrary commands via shell metacharacters in a filename.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/axkibe/lsyncd/issues/220","https://www.cve.org/CVERecord?id=CVE-2014-8990"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=767227"],"patches":{"lsyncd":[]},"tags":{},"packages":[{"name":"lsyncd","source":"https://ubuntu.com/security/cve?package=lsyncd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lsyncd","debian":"https://tracker.debian.org/pkg/lsyncd","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.5-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.1.5-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.1.5-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-8123","published":"2014-12-05T16:59:00","updated_at":"2025-07-17T16:42:40.815870+00:00","description":"\nBuffer overflow in the bGetPPS function in wordole.c in Antiword 0.37\nallows remote attackers to cause a denial of service (crash) via a crafted\ndocument.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"was fixed in 0.37-5"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/12/01/4","https://www.cve.org/CVERecord?id=CVE-2014-8123"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771768"],"patches":{"antiword":[]},"tags":{},"packages":[{"name":"antiword","source":"https://ubuntu.com/security/cve?package=antiword","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=antiword","debian":"https://tracker.debian.org/pkg/antiword","statuses":[{"release_codename":"lucid","status":"not-affected","description":"0.37-6","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.37-5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":64360,"limit":20,"total_results":79316}