{"cves":[{"id":"CVE-2014-4414","published":"2014-09-18T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site, a different\nvulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and\nAPPLE-SA-2014-09-17-2.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://support.apple.com/kb/HT6440","http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html","http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","https://www.cve.org/CVERecord?id=CVE-2014-4414"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4413","published":"2014-09-18T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site, a different\nvulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and\nAPPLE-SA-2014-09-17-2.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://support.apple.com/kb/HT6440","http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html","http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","https://www.cve.org/CVERecord?id=CVE-2014-4413"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4412","published":"2014-09-18T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site, a different\nvulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and\nAPPLE-SA-2014-09-17-2.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://support.apple.com/kb/HT6440","http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html","http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","https://www.cve.org/CVERecord?id=CVE-2014-4412"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4411","published":"2014-09-18T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site, a different\nvulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and\nAPPLE-SA-2014-09-17-2.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://support.apple.com/kb/HT6440","http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html","http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","https://www.cve.org/CVERecord?id=CVE-2014-4411"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4410","published":"2014-09-18T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site, a different\nvulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and\nAPPLE-SA-2014-09-17-2.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://support.apple.com/kb/HT6440","http://archives.neohapsis.com/archives/bugtraq/2014-09/0107.html","http://archives.neohapsis.com/archives/bugtraq/2014-09/0106.html","https://www.cve.org/CVERecord?id=CVE-2014-4410"],"bugs":[""],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2886","published":"2014-09-18T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGKSu 2.0.2, when sudo-mode is not enabled, uses \" (double quote) characters\nin a gksu-run-helper argument, which allows attackers to execute arbitrary\ncommands in certain situations involving an untrusted substring within this\nargument, as demonstrated by an untrusted filename encountered during\ninstallation of a VirtualBox extension pack.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in Ubuntu, sudo-mode is the default, and the root account has\nno password. On top of that, the fault actually lies in\nVirtualBox that is not properly escaping the filename before\ncalling gksu."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://community.rapid7.com/community/metasploit/blog/2014/07/07/virtualbox-filename-command-execution-via-gksu","https://launchpad.net/bugs/1186676","http://savannah.nongnu.org/bugs/?40023","https://www.cve.org/CVERecord?id=CVE-2014-2886"],"bugs":[""],"patches":{"gksu":[]},"tags":{},"packages":[{"name":"gksu","source":"https://ubuntu.com/security/cve?package=gksu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gksu","debian":"https://tracker.debian.org/pkg/gksu","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0568","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe NtSetInformationFile system call hook feature in Adobe Reader and\nAcrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows\nattackers to bypass a sandbox protection mechanism, and consequently\nexecute native code in a privileged context, via an NTFS junction attack.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only Windows and OS X are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0568"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0567","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12\nand 11.x before 11.0.09 on Windows and OS X allows attackers to execute\narbitrary code via unspecified vectors, a different vulnerability than\nCVE-2014-0561.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only Windows and OS X are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0567"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0566","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on\nWindows and OS X allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2014-0565.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only Windows and OS X are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0566"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0565","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on\nWindows and OS X allow attackers to execute arbitrary code or cause a\ndenial of service (memory corruption) via unspecified vectors, a different\nvulnerability than CVE-2014-0566.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only Windows and OS X are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0565"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0563","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on\nWindows and OS X allow attackers to cause a denial of service (memory\ncorruption) via unspecified vectors.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only Windows and OS X are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0563"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0562","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x\nbefore 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to\ninject arbitrary web script or HTML via unspecified vectors, aka \"Universal\nXSS (UXSS).\"","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only OS X is affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0562"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0561","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12\nand 11.x before 11.0.09 on Windows and OS X allows attackers to execute\narbitrary code via unspecified vectors, a different vulnerability than\nCVE-2014-0567.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only Windows and OS X are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0561"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0560","published":"2014-09-17T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Adobe Reader and Acrobat 10.x before\n10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to\nexecute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only Windows and OS X are affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/reader/apsb14-20.html","https://www.cve.org/CVERecord?id=CVE-2014-0560"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.1.12, 11.0.09","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3639","published":"2014-09-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not\nproperly close old connections, which allows local users to cause a denial\nof service (incomplete connection consumption and prevention of new\nconnections) via a large number of incomplete connections.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/09/16/9","https://ubuntu.com/security/notices/USN-2352-1","https://www.cve.org/CVERecord?id=CVE-2014-3639"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=80919"],"patches":{"dbus":["upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=54d26df52b6a394bea175651d1d7ad2ab3f87dea","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=8ad179a8dad789fc6a5402780044bc0ec3d41115","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=a3477feb7aa8658602cceb8d29ae370a83002172","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=89219baab0bf6ff05142518110f45c8159be8092"]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"lucid","status":"released","description":"1.2.16-2ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.4.18-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.18-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.24,1.8.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-2352-1"],"notices":[{"id":"USN-2352-1","title":"DBus vulnerabilities","summary":"Several security issues were fixed in DBus.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-09-22T17:08:16.072719","description":"Simon McVittie discovered that DBus incorrectly handled the file\ndescriptors message limit. A local attacker could use this issue to cause\nDBus to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-3635)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nfile descriptor messages. A local attacker could use this issue to cause\nDBus to stop responding, resulting in a denial of service. This issue only\napplied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)\n\nAlban Crequy discovered that DBus incorrectly handled certain file\ndescriptor messages. A local attacker could use this issue to cause DBus\nto maintain persistent connections, possibly resulting in a denial of\nservice. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\n(CVE-2014-3637)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nparallel connections and parallel message calls. A local attacker could use\nthis issue to cause DBus to consume resources, possibly resulting in a\ndenial of service. (CVE-2014-3638)\n\nAlban Crequy discovered that DBus incorrectly handled incomplete\nconnections. A local attacker could use this issue to cause DBus to fail\nlegitimate connection attempts, resulting in a denial of service.\n(CVE-2014-3639)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"dbus","version":"1.2.16-2ubuntu4.8","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"},{"name":"libdbus-1-3","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"}],"precise":[{"name":"dbus","version":"1.4.18-1ubuntu1.6","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"},{"name":"libdbus-1-3","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"}],"trusty":[{"name":"dbus","version":"1.6.18-0ubuntu4.2","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-1-doc","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-x11","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-3","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-dev","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3635","CVE-2014-3636","CVE-2014-3637","CVE-2014-3638","CVE-2014-3639"]}]},{"id":"CVE-2014-3638","published":"2014-09-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe bus_connections_check_reply function in config-parser.c in D-Bus before\n1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of\nservice (CPU consumption) via a large number of method calls.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/09/16/9","https://ubuntu.com/security/notices/USN-2352-1","https://www.cve.org/CVERecord?id=CVE-2014-3638"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=81053"],"patches":{"dbus":["upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=5bc7f9519ebc6117ba300c704794b36b87c2194b","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=6060aaa0ea1e9bbe1dd7a1864c8df52e333a45ee"]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"lucid","status":"released","description":"1.2.16-2ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.4.18-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.18-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.24,1.8.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-2352-1"],"notices":[{"id":"USN-2352-1","title":"DBus vulnerabilities","summary":"Several security issues were fixed in DBus.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-09-22T17:08:16.072719","description":"Simon McVittie discovered that DBus incorrectly handled the file\ndescriptors message limit. A local attacker could use this issue to cause\nDBus to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-3635)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nfile descriptor messages. A local attacker could use this issue to cause\nDBus to stop responding, resulting in a denial of service. This issue only\napplied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)\n\nAlban Crequy discovered that DBus incorrectly handled certain file\ndescriptor messages. A local attacker could use this issue to cause DBus\nto maintain persistent connections, possibly resulting in a denial of\nservice. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\n(CVE-2014-3637)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nparallel connections and parallel message calls. A local attacker could use\nthis issue to cause DBus to consume resources, possibly resulting in a\ndenial of service. (CVE-2014-3638)\n\nAlban Crequy discovered that DBus incorrectly handled incomplete\nconnections. A local attacker could use this issue to cause DBus to fail\nlegitimate connection attempts, resulting in a denial of service.\n(CVE-2014-3639)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"dbus","version":"1.2.16-2ubuntu4.8","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"},{"name":"libdbus-1-3","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"}],"precise":[{"name":"dbus","version":"1.4.18-1ubuntu1.6","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"},{"name":"libdbus-1-3","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"}],"trusty":[{"name":"dbus","version":"1.6.18-0ubuntu4.2","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-1-doc","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-x11","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-3","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-dev","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3635","CVE-2014-3636","CVE-2014-3637","CVE-2014-3638","CVE-2014-3639"]}]},{"id":"CVE-2014-3637","published":"2014-09-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nD-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not\nproperly close connections for processes that have terminated, which allows\nlocal users to cause a denial of service via a D-bus message containing a\nD-Bus connection file descriptor.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects >= 1.3.0"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/09/16/9","https://ubuntu.com/security/notices/USN-2352-1","https://www.cve.org/CVERecord?id=CVE-2014-3637"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=80559"],"patches":{"dbus":["upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=bbf11cd5f92064c7c8af61ad4d9ff41f3a039abc","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=995734750cea65012537748ee56488c707d2f027","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=8021fd84267ee1394d96f4a119adb57de3971a62","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=e0c9d31be3b9eea9ee2a3a255bc2cf9aad713642","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=e17a921be676bcc89373ec1a9f368fe8b36f1073","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=52abb5172f7426bb3f1dbe63a2b3a2d2ea7e7ac2","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=01e32d6ddcfdcbd63cf1c8053f6e5d2ffdfbaa91","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=b027c421de0bc3858cc1139149c613958100c2bd"]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"lucid","status":"not-affected","description":"1.2.16-2ubuntu4.7","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.4.18-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.18-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.24,1.8.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-2352-1"],"notices":[{"id":"USN-2352-1","title":"DBus vulnerabilities","summary":"Several security issues were fixed in DBus.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-09-22T17:08:16.072719","description":"Simon McVittie discovered that DBus incorrectly handled the file\ndescriptors message limit. A local attacker could use this issue to cause\nDBus to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-3635)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nfile descriptor messages. A local attacker could use this issue to cause\nDBus to stop responding, resulting in a denial of service. This issue only\napplied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)\n\nAlban Crequy discovered that DBus incorrectly handled certain file\ndescriptor messages. A local attacker could use this issue to cause DBus\nto maintain persistent connections, possibly resulting in a denial of\nservice. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\n(CVE-2014-3637)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nparallel connections and parallel message calls. A local attacker could use\nthis issue to cause DBus to consume resources, possibly resulting in a\ndenial of service. (CVE-2014-3638)\n\nAlban Crequy discovered that DBus incorrectly handled incomplete\nconnections. A local attacker could use this issue to cause DBus to fail\nlegitimate connection attempts, resulting in a denial of service.\n(CVE-2014-3639)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"dbus","version":"1.2.16-2ubuntu4.8","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"},{"name":"libdbus-1-3","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"}],"precise":[{"name":"dbus","version":"1.4.18-1ubuntu1.6","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"},{"name":"libdbus-1-3","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"}],"trusty":[{"name":"dbus","version":"1.6.18-0ubuntu4.2","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-1-doc","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-x11","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-3","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-dev","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3635","CVE-2014-3636","CVE-2014-3637","CVE-2014-3638","CVE-2014-3639"]}]},{"id":"CVE-2014-3636","published":"2014-09-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nD-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local\nusers to (1) cause a denial of service (prevention of new connections and\nconnection drop) by queuing the maximum number of file descriptors or (2)\ncause a denial of service (disconnect) via multiple messages that combine\nto have more than the allowed number of file descriptors for a single\nsendmsg call.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"commit in 1.6 seems to have wrong header\nonly affects >= 1.3.0"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/09/16/9","https://ubuntu.com/security/notices/USN-2352-1","https://www.cve.org/CVERecord?id=CVE-2014-3636"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=82820"],"patches":{"dbus":["upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=6465e37c8ff70a714e302d0c9e6534fa6181fce6","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=346da99f7620e6901e7c7babd4590fcc5aac32bf"]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"lucid","status":"not-affected","description":"1.2.16-2ubuntu4.7","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.4.18-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.18-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.24,1.8.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-2352-1"],"notices":[{"id":"USN-2352-1","title":"DBus vulnerabilities","summary":"Several security issues were fixed in DBus.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-09-22T17:08:16.072719","description":"Simon McVittie discovered that DBus incorrectly handled the file\ndescriptors message limit. A local attacker could use this issue to cause\nDBus to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-3635)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nfile descriptor messages. A local attacker could use this issue to cause\nDBus to stop responding, resulting in a denial of service. This issue only\napplied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)\n\nAlban Crequy discovered that DBus incorrectly handled certain file\ndescriptor messages. A local attacker could use this issue to cause DBus\nto maintain persistent connections, possibly resulting in a denial of\nservice. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\n(CVE-2014-3637)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nparallel connections and parallel message calls. A local attacker could use\nthis issue to cause DBus to consume resources, possibly resulting in a\ndenial of service. (CVE-2014-3638)\n\nAlban Crequy discovered that DBus incorrectly handled incomplete\nconnections. A local attacker could use this issue to cause DBus to fail\nlegitimate connection attempts, resulting in a denial of service.\n(CVE-2014-3639)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"dbus","version":"1.2.16-2ubuntu4.8","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"},{"name":"libdbus-1-3","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"}],"precise":[{"name":"dbus","version":"1.4.18-1ubuntu1.6","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"},{"name":"libdbus-1-3","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"}],"trusty":[{"name":"dbus","version":"1.6.18-0ubuntu4.2","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-1-doc","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-x11","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-3","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-dev","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3635","CVE-2014-3636","CVE-2014-3637","CVE-2014-3638","CVE-2014-3639"]}]},{"id":"CVE-2014-3635","published":"2014-09-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x\nbefore 1.8.8, when running on a 64-bit system and the max_message_unix_fds\nlimit is set to an odd number, allows local users to cause a denial of\nservice (dbus-daemon crash) or possibly execute arbitrary code by sending\none more file descriptor than the limit, which triggers a heap-based buffer\noverflow or an assertion failure.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects >= 1.3.0"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/09/16/9","https://ubuntu.com/security/notices/USN-2352-1","https://www.cve.org/CVERecord?id=CVE-2014-3635"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=83622"],"patches":{"dbus":["upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=f70c0e98c5cc6eaae4727d14c389e2504e79e694","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?id=ee11ec12566afda5dee8a3a834274421a20661de","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=b1e9a2b4bd858b37c0bc02aa102b97530083a703","upstream: http://cgit.freedesktop.org/dbus/dbus/commit/?h=dbus-1.6&id=94b8d5e7a85bfb6c9a92b8e22e382b2e0ded2b59"]},"tags":{},"packages":[{"name":"dbus","source":"https://ubuntu.com/security/cve?package=dbus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dbus","debian":"https://tracker.debian.org/pkg/dbus","statuses":[{"release_codename":"lucid","status":"not-affected","description":"1.2.16-2ubuntu4.7","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.4.18-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.6.18-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.24,1.8.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-2352-1"],"notices":[{"id":"USN-2352-1","title":"DBus vulnerabilities","summary":"Several security issues were fixed in DBus.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-09-22T17:08:16.072719","description":"Simon McVittie discovered that DBus incorrectly handled the file\ndescriptors message limit. A local attacker could use this issue to cause\nDBus to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only applied to Ubuntu 12.04 LTS and Ubuntu\n14.04 LTS. (CVE-2014-3635)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nfile descriptor messages. A local attacker could use this issue to cause\nDBus to stop responding, resulting in a denial of service. This issue only\napplied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-3636)\n\nAlban Crequy discovered that DBus incorrectly handled certain file\ndescriptor messages. A local attacker could use this issue to cause DBus\nto maintain persistent connections, possibly resulting in a denial of\nservice. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.\n(CVE-2014-3637)\n\nAlban Crequy discovered that DBus incorrectly handled a large number of\nparallel connections and parallel message calls. A local attacker could use\nthis issue to cause DBus to consume resources, possibly resulting in a\ndenial of service. (CVE-2014-3638)\n\nAlban Crequy discovered that DBus incorrectly handled incomplete\nconnections. A local attacker could use this issue to cause DBus to fail\nlegitimate connection attempts, resulting in a denial of service.\n(CVE-2014-3639)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"dbus","version":"1.2.16-2ubuntu4.8","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"},{"name":"libdbus-1-3","version":"1.2.16-2ubuntu4.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.2.16-2ubuntu4.8"}],"precise":[{"name":"dbus","version":"1.4.18-1ubuntu1.6","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"},{"name":"libdbus-1-3","version":"1.4.18-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.4.18-1ubuntu1.6"}],"trusty":[{"name":"dbus","version":"1.6.18-0ubuntu4.2","description":"simple interprocess messaging system","is_source":true},{"name":"dbus","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-1-doc","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"dbus-x11","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-3","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"},{"name":"libdbus-1-dev","version":"1.6.18-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dbus","version_link":"https://launchpad.net/ubuntu/+source/dbus/1.6.18-0ubuntu4.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3635","CVE-2014-3636","CVE-2014-3637","CVE-2014-3638","CVE-2014-3639"]}]},{"id":"CVE-2014-3616","published":"2014-09-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or\nssl_session_ticket_key for multiple servers, can reuse a cached SSL session\nfor an unrelated context, which allows remote attackers with certain\nprivileges to conduct \"virtual host confusion\" attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://bh.ht.vc/vhost_confusion.pdf","https://ubuntu.com/security/notices/USN-2351-1","https://www.cve.org/CVERecord?id=CVE-2014-3616"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1370478","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=761940"],"patches":{"nginx":["upstream: http://trac.nginx.org/nginx/changeset/1ee1db30c9b96e9e43e85ab0bfba42140af24966/nginx"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.1.19-1ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.5,1.6.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.6.2-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2351-1"],"notices":[{"id":"USN-2351-1","title":"nginx vulnerability","summary":"nginx could be made to expose sensitive information over the network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-22T16:32:19.124134","description":"Antoine Delignat-Lavaud and Karthikeyan Bhargavan discovered that nginx\nincorrectly reused cached SSL sessions. An attacker could possibly use this\nissue in certain configurations to obtain access to information from a\ndifferent virtual host.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.1","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3616"]}]}],"offset":64860,"limit":20,"total_results":79316}