{"cves":[{"id":"CVE-2014-3542","published":"2014-07-29T11:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x\nbefore 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote\nattackers to read arbitrary files via an XML external entity declaration in\nconjunction with an entity reference, related to an XML External Entity\n(XXE) issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-45463","http://seclists.org/oss-sec/2014/q3/194","https://www.cve.org/CVERecord?id=CVE-2014-3542"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.1, 2.6.4, 2.5.7 and 2.4.11","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3541","published":"2014-07-29T11:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11,\n2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows\nremote attackers to conduct PHP object injection attacks and execute\narbitrary code via serialized data associated with an add-on.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-45616","http://seclists.org/oss-sec/2014/q3/194","https://www.cve.org/CVERecord?id=CVE-2014-3541"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.1, 2.6.4, 2.5.7 and 2.4.11","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.7.5+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5031","published":"2014-07-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe web interface in CUPS before 2.0 does not check that files have\nworld-readable permissions, which allows remote attackers to obtains\nsensitive information via unspecified vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"The patch below introduces a regression preventing the web\ninterface from being able to read log files. (See comments in\nbug 4455.)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2014/q3/209","https://ubuntu.com/security/notices/USN-2341-1","https://www.cve.org/CVERecord?id=CVE-2014-5031"],"bugs":["https://cups.org/str.php?L4455","https://cups.org/str.php?L4461","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=757964","https://bugs.launchpad.net/ubuntu/+source/cups/+bug/1349387"],"patches":{"cups":["upstream: https://cups.org/strfiles.php/3371/str4455-1.7.patch"]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"lucid","status":"released","description":"1.4.3-1ubuntu1.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.5.3-0ubuntu8.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.7.2-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.4-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-2341-1"],"notices":[{"id":"USN-2341-1","title":"CUPS vulnerabilities","summary":"CUPS could be made to expose sensitive information, leading to privilege\nescalation.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-08T14:17:56.405424","description":"Salvatore Bonaccorso discovered that the CUPS web interface incorrectly\nvalidated permissions and incorrectly handled symlinks. An attacker could\npossibly use this issue to bypass file permissions and read arbitrary\nfiles, possibly leading to a privilege escalation.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"cups","version":"1.4.3-1ubuntu1.13","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.4.3-1ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.3-1ubuntu1.13"}],"precise":[{"name":"cups","version":"1.5.3-0ubuntu8.5","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.5.3-0ubuntu8.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.5.3-0ubuntu8.5"}],"trusty":[{"name":"cups","version":"1.7.2-0ubuntu1.2","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-bsd","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-client","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-common","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-core-drivers","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-daemon","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-ppdc","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-server-common","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcups2","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcups2-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupscgi1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupscgi1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsimage2","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsimage2-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsmime1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsmime1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsppdc1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsppdc1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-5029","CVE-2014-5030","CVE-2014-5031"]}]},{"id":"CVE-2014-5030","published":"2014-07-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCUPS before 2.0 allows local users to read arbitrary files via a symlink\nattack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5)\nindex.pyc, or (6) index.py.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"The patch below introduces a regression preventing the web\ninterface from being able to read log files. (See comments in\nbug 4455.)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2014/q3/209","https://ubuntu.com/security/notices/USN-2341-1","https://www.cve.org/CVERecord?id=CVE-2014-5030"],"bugs":["https://cups.org/str.php?L4455","https://cups.org/str.php?L4461"],"patches":{"cups":["upstream: https://cups.org/strfiles.php/3371/str4455-1.7.patch"]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"lucid","status":"released","description":"1.4.3-1ubuntu1.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.5.3-0ubuntu8.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.7.2-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.4-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-2341-1"],"notices":[{"id":"USN-2341-1","title":"CUPS vulnerabilities","summary":"CUPS could be made to expose sensitive information, leading to privilege\nescalation.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-08T14:17:56.405424","description":"Salvatore Bonaccorso discovered that the CUPS web interface incorrectly\nvalidated permissions and incorrectly handled symlinks. An attacker could\npossibly use this issue to bypass file permissions and read arbitrary\nfiles, possibly leading to a privilege escalation.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"cups","version":"1.4.3-1ubuntu1.13","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.4.3-1ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.3-1ubuntu1.13"}],"precise":[{"name":"cups","version":"1.5.3-0ubuntu8.5","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.5.3-0ubuntu8.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.5.3-0ubuntu8.5"}],"trusty":[{"name":"cups","version":"1.7.2-0ubuntu1.2","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-bsd","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-client","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-common","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-core-drivers","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-daemon","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-ppdc","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-server-common","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcups2","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcups2-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupscgi1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupscgi1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsimage2","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsimage2-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsmime1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsmime1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsppdc1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsppdc1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-5029","CVE-2014-5030","CVE-2014-5031"]}]},{"id":"CVE-2014-5029","published":"2014-07-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe web interface in CUPS 1.7.4 allows local users in the lp group to read\narbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and\nlanguage[0] set to null.  NOTE: this vulnerability exists because of an\nincomplete fix for CVE-2014-3537.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"The patch below introduces a regression preventing the web\ninterface from being able to read log files. (See comments in\nbug 4455.)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/oss-sec/2014/q3/209","https://ubuntu.com/security/notices/USN-2341-1","https://www.cve.org/CVERecord?id=CVE-2014-5029"],"bugs":["https://cups.org/str.php?L4455","https://cups.org/str.php?L4461"],"patches":{"cups":["upstream: https://cups.org/strfiles.php/3371/str4455-1.7.patch"]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"lucid","status":"released","description":"1.4.3-1ubuntu1.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.5.3-0ubuntu8.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.7.2-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.4-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-2341-1"],"notices":[{"id":"USN-2341-1","title":"CUPS vulnerabilities","summary":"CUPS could be made to expose sensitive information, leading to privilege\nescalation.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-09-08T14:17:56.405424","description":"Salvatore Bonaccorso discovered that the CUPS web interface incorrectly\nvalidated permissions and incorrectly handled symlinks. An attacker could\npossibly use this issue to bypass file permissions and read arbitrary\nfiles, possibly leading to a privilege escalation.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"cups","version":"1.4.3-1ubuntu1.13","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.4.3-1ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.3-1ubuntu1.13"}],"precise":[{"name":"cups","version":"1.5.3-0ubuntu8.5","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.5.3-0ubuntu8.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.5.3-0ubuntu8.5"}],"trusty":[{"name":"cups","version":"1.7.2-0ubuntu1.2","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-bsd","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-client","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-common","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-core-drivers","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-daemon","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-ppdc","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"cups-server-common","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcups2","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcups2-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupscgi1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupscgi1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsimage2","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsimage2-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsmime1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsmime1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsppdc1","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"},{"name":"libcupsppdc1-dev","version":"1.7.2-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.2-0ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-5029","CVE-2014-5030","CVE-2014-5031"]}]},{"id":"CVE-2014-0475","published":"2014-07-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple directory traversal vulnerabilities in GNU C Library (aka glibc or\nlibc6) before 2.20 allow context-dependent attackers to bypass ForceCommand\nrestrictions and possibly have other unspecified impact via a .. (dot dot)\nin a (1) LC_*, (2) LANG, or other locale environment variable.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"The fix for this introduced a localplt regression"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2306-1","https://www.cve.org/CVERecord?id=CVE-2014-0475"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=17137"],"patches":{"eglibc":[],"glibc":["upstream: https://sourceware.org/git/?p=glibc.git;h=4e8f95a0df7c2300b830ec12c0ae1e161bc8a8a3","upstream: https://sourceware.org/git/?p=glibc.git;h=585367266923156ac6fb789939a923641ba5aaf4","upstream: https://sourceware.org/git/?p=glibc.git;h=d183645616b0533b3acee28f1a95570bffbdf50f","upstream: https://sourceware.org/git/?p=glibc.git;h=ca38dc17d85b09776a709c8ea7155c414df14073"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"lucid","status":"released","description":"2.11.1-0ubuntu7.14","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.6","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.19-0ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.19-7","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.19-6","component":null,"pocket":"security"}]}],"notices_ids":["USN-2306-1"],"notices":[{"id":"USN-2306-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-08-04T15:37:16.011728","description":"Maksymilian Arciemowicz discovered that the GNU C Library incorrectly\nhandled the getaddrinfo() function. An attacker could use this issue to\ncause a denial of service. This issue only affected Ubuntu 10.04 LTS.\n(CVE-2013-4357)\n\nIt was discovered that the GNU C Library incorrectly handled the\ngetaddrinfo() function. An attacker could use this issue to cause a denial\nof service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS.\n(CVE-2013-4458)\n\nStephane Chazelas discovered that the GNU C Library incorrectly handled\nlocale environment variables. An attacker could use this issue to possibly\nbypass certain restrictions such as the ForceCommand restrictions in\nOpenSSH. (CVE-2014-0475)\n\nDavid Reid, Glyph Lefkowitz, and Alex Gaynor discovered that the GNU C\nLibrary incorrectly handled posix_spawn_file_actions_addopen() path\narguments. An attacker could use this issue to cause a denial of service.\n(CVE-2014-4043)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"eglibc","version":"2.11.1-0ubuntu7.14","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.11.1-0ubuntu7.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.11.1-0ubuntu7.14"}],"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.6","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.6"}],"trusty":[{"name":"eglibc","version":"2.19-0ubuntu6.1","description":"GNU C Library","is_source":true},{"name":"eglibc-source","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"glibc-doc","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc-bin","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc-dev-bin","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-amd64","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-armel","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-dev","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-dev-armel","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-dev-i386","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-dev-x32","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-i386","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-pic","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-ppc64","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-prof","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-udeb","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libc6-x32","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libnss-dns-udeb","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"libnss-files-udeb","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"multiarch-support","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"},{"name":"nscd","version":"2.19-0ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-4357","CVE-2013-4458","CVE-2014-0475","CVE-2014-4043"]}]},{"id":"CVE-2013-7393","published":"2014-07-28T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users\nto gain privileges via a symlink attack on the pid file created for (1)\nsvnwcsub.py or (2) irkerbridge.py when the --pidfile option is used.  NOTE:\nthis issue was SPLIT from CVE-2013-4262 based on different affected\nversions (ADT3).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"split off from CVE-2013-4262\n1.8.x only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://subversion.apache.org/security/CVE-2013-4262-advisory.txt","https://www.cve.org/CVERecord?id=CVE-2013-7393"],"bugs":[""],"patches":{"subversion":[]},"tags":{},"packages":[{"name":"subversion","source":"https://ubuntu.com/security/cve?package=subversion","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=subversion","debian":"https://tracker.debian.org/pkg/subversion","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.6.17dfsg-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1.8.8-1ubuntu3]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5015","published":"2014-07-24T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nbozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD,\ntruncates paths when checking .htpasswd restrictions, which allows remote\nattackers to bypass the HTTP authentication scheme and access restrictions\nvia a long path.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=140572157701095&w=2","http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-007.txt.asc","http://www.eterna.com.au/bozohttpd/","https://www.cve.org/CVERecord?id=CVE-2014-5015"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=755197"],"patches":{"bozohttpd":[]},"tags":{},"packages":[{"name":"bozohttpd","source":"https://ubuntu.com/security/cve?package=bozohttpd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bozohttpd","debian":"https://tracker.debian.org/pkg/bozohttpd","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"20111118-1+deb7u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20140708","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4927","published":"2014-07-24T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and\nDSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote\nattackers to cause a denial of service (crash) via a long string in the URI\nin a GET request.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"No source control or issue tracker for micro-httpd"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.exploit-db.com/exploits/34102","http://packetstormsecurity.com/files/127544/ACME-micro_httpd-Denial-Of-Service.html","http://osvdb.org/show/osvdb/109356","https://www.cve.org/CVERecord?id=CVE-2014-4927"],"bugs":[""],"patches":{"micro-httpd":[]},"tags":{},"packages":[{"name":"micro-httpd","source":"https://ubuntu.com/security/cve?package=micro-httpd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=micro-httpd","debian":"https://tracker.debian.org/pkg/micro-httpd","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4910","published":"2014-07-24T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in tools/backlight_helper.c in X.Org\nxf86-video-intel 2.99.911 allows remote attackers to create or overwrite\narbitrary files via a .. (dot dot) in the interface name.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"added in 2.99.911"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.x.org/archives/xorg-commit/2014-July/036840.html","http://www.openwall.com/lists/oss-security/2014/07/11","https://www.cve.org/CVERecord?id=CVE-2014-4910"],"bugs":[""],"patches":{"xserver-xorg-video-intel":[]},"tags":{},"packages":[{"name":"xserver-xorg-video-intel","source":"https://ubuntu.com/security/cve?package=xserver-xorg-video-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xserver-xorg-video-intel","debian":"https://tracker.debian.org/pkg/xserver-xorg-video-intel","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4503","published":"2014-07-23T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe parse_notify function in util.c in sgminer before 4.2.2 and cgminer\n3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of\nservice (application exit) via a crafted (1) bbversion, (2) prev_hash, (3)\nnbit, or (4) ntime parameter in a mining.notify action stratum message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/sgminer-dev/sgminer/commit/910c36089940e81fb85c65b8e63dcd2fac71470c","http://seclists.org/fulldisclosure/2014/Jul/120","https://www.cve.org/CVERecord?id=CVE-2014-4503"],"bugs":[""],"patches":{"cgminer":["other: https://github.com/sgminer-dev/sgminer/commit/910c36089940e81fb85c65b8e63dcd2fac71470c"]},"tags":{},"packages":[{"name":"cgminer","source":"https://ubuntu.com/security/cve?package=cgminer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cgminer","debian":"https://tracker.debian.org/pkg/cgminer","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4502","published":"2014-07-23T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple heap-based buffer overflows in the parse_notify function in\nsgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow\nremote pool servers to have unspecified impact via a (1) large or (2)\nnegative value in the Extranonc2_size parameter in a mining.subscribe\nresponse and a crafted mining.notify request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/sgminer-dev/sgminer/commit/bac5831b355f916e0696b7bbcccfc51c057b729a","https://github.com/luke-jr/bfgminer/commit/ff7f30129f15f7a2213f8ced0cd65c9a331493d9","https://github.com/ckolivas/cgminer/commit/e1c5050734123973b99d181c45e74b2cbb00272e","https://github.com/sgminer-dev/sgminer/issues/258","http://seclists.org/fulldisclosure/2014/Jul/119","https://www.cve.org/CVERecord?id=CVE-2014-4502"],"bugs":[""],"patches":{"cgminer":["upstream: https://github.com/ckolivas/cgminer/commit/e1c5050734123973b99d181c45e74b2cbb00272e"],"bfgminer":["upstream: https://github.com/luke-jr/bfgminer/commit/ff7f30129f15f7a2213f8ced0cd65c9a331493d9"]},"tags":{},"packages":[{"name":"bfgminer","source":"https://ubuntu.com/security/cve?package=bfgminer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bfgminer","debian":"https://tracker.debian.org/pkg/bfgminer","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.1.0","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"cgminer","source":"https://ubuntu.com/security/cve?package=cgminer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cgminer","debian":"https://tracker.debian.org/pkg/cgminer","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-4501","published":"2014-07-23T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in sgminer before 4.2.2, cgminer\nbefore 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have\nunspecified impact via a long URL in a client.reconnect stratum message to\nthe (1) extract_sockaddr or (2) parse_reconnect functions in util.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/sgminer-dev/sgminer/commit/b65574bef233474e915fdf18614aa211e31cc6c2","https://github.com/sgminer-dev/sgminer/commit/78cc408369bdbbd440196c93574098d1482efbce","https://github.com/luke-jr/bfgminer/commit/c80ad8548251eb0e15329fc240c89070640c9d79","https://github.com/ckolivas/cgminer/commit/e1c5050734123973b99d181c45e74b2cbb00272e","http://seclists.org/fulldisclosure/2014/Jul/118","https://www.cve.org/CVERecord?id=CVE-2014-4501"],"bugs":[""],"patches":{"cgminer":["upstream: https://github.com/ckolivas/cgminer/commit/e1c5050734123973b99d181c45e74b2cbb00272e"],"bfgminer":["upstream: https://github.com/luke-jr/bfgminer/commit/c80ad8548251eb0e15329fc240c89070640c9d79"]},"tags":{},"packages":[{"name":"bfgminer","source":"https://ubuntu.com/security/cve?package=bfgminer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bfgminer","debian":"https://tracker.debian.org/pkg/bfgminer","statuses":[{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3.0","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"cgminer","source":"https://ubuntu.com/security/cve?package=cgminer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cgminer","debian":"https://tracker.debian.org/pkg/cgminer","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-1551","published":"2014-07-23T11:12:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the FontTableRec destructor in Mozilla\nFirefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before\n24.7 on Windows allows remote attackers to execute arbitrary code via\ncrafted use of fonts in MathML content, leading to improper handling of a\nDirectWrite font-face object.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Windows-specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.mozilla.org/security/announce/2014/mfsa2014-59.html","https://www.cve.org/CVERecord?id=CVE-2014-1551"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5033","published":"2014-07-23T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nKDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus\nfor communication with a polkit authority, which allows local users to\nbypass intended access restrictions by leveraging a PolkitUnixProcess\nPolkitSubject race condition via a (1) setuid process or (2) pkexec\nprocess, related to CVE-2013-4288 and \"PID reuse race conditions.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2304-1","https://www.cve.org/CVERecord?id=CVE-2014-5033"],"bugs":["https://bugzilla.novell.com/show_bug.cgi?id=864716","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=755814","https://bugs.launchpad.net/ubuntu/+source/kde4libs/+bug/1350019"],"patches":{"kde4libs":["upstream: http://quickgit.kde.org/?p=kdelibs.git&a=commit&h=e4e7b53b71e2659adaf52691d4accc3594203b23"]},"tags":{},"packages":[{"name":"kde4libs","source":"https://ubuntu.com/security/cve?package=kde4libs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kde4libs","debian":"https://tracker.debian.org/pkg/kde4libs","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:4.8.5-0ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4:4.13.2a-0ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2304-1"],"notices":[{"id":"USN-2304-1","title":"KDE-Libs vulnerability","summary":"kauth could be tricked into bypassing polkit authorizations.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-07-31T13:48:33.615512","description":"It was discovered that kauth was using polkit in an unsafe manner. A local\nattacker could possibly use this issue to bypass intended polkit\nauthorizations.\n","is_hidden":false,"release_packages":{"precise":[{"name":"kde4libs","version":"4:4.8.5-0ubuntu0.4","description":"KDE 4 core applications and libraries","is_source":true},{"name":"kdelibs5-plugins","version":"4:4.8.5-0ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.8.5-0ubuntu0.4"}],"trusty":[{"name":"kde4libs","version":"4:4.13.2a-0ubuntu0.3","description":"KDE 4 core applications and libraries","is_source":true},{"name":"kdelibs-bin","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"kdelibs5-data","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"kdelibs5-dev","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"kdelibs5-plugins","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"kdoctools","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkcmutils4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkde3support4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkdeclarative5","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkdecore5","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkdesu5","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkdeui5","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkdewebkit5","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkdnssd4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkemoticons4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkfile4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkhtml5","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkidletime4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkimproxy4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkio5","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkjsapi4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkjsembed4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkmediaplayer4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libknewstuff2-4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libknewstuff3-4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libknotifyconfig4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkntlm4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkparts4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkprintutils4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkpty4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkrosscore4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkrossui4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libktexteditor4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkunitconversion4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libkutils4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libnepomuk4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libnepomukquery4a","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libnepomukutils4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libplasma3","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libsolid4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"},{"name":"libthreadweaver4","version":"4:4.13.2a-0ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kde4libs","version_link":"https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.2a-0ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-5033"]}]},{"id":"CVE-2014-3555","published":"2014-07-23T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before\nJuno-2 allows remote authenticated users to cause a denial of service\n(crash or long firewall rule updates) by creating a large number of allowed\naddress pairs.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"requires authenticated access"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.openstack.org/pipermail/openstack-announce/2014-July/000255.html","https://ubuntu.com/security/notices/USN-2321-1","https://www.cve.org/CVERecord?id=CVE-2014-3555"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=755134","https://bugs.launchpad.net/ubuntu/+source/nova/+bug/1354159 (2014.1.2)","http://launchpad.net/bugs/1336207"],"patches":{"neutron":["upstream: https://review.openstack.org/gitweb?p=openstack%2Fneutron.git;a=commitdiff;h=2c4828e28a5ff6e537be9db4da0e98eca33135d5"]},"tags":{},"packages":[{"name":"neutron","source":"https://ubuntu.com/security/cve?package=neutron","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=neutron","debian":"https://tracker.debian.org/pkg/neutron","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2014.1.1-3,2014.1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:2014.1.2-0ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2321-1"],"notices":[{"id":"USN-2321-1","title":"OpenStack Neutron vulnerabilities","summary":"OpenStack Neutron could be made to expose sensitive information or crash.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-08-21T20:18:34.656356","description":"Liping Mao discovered that OpenStack Neutron did not properly handle\nrequests for a large number of allowed address pairs. A remote\nauthenticated attacker could exploit this to cause a denial of service.\n(CVE-2014-3555)\n\nZhi Kun Liu discovered that OpenStack Neutron incorrectly filtered certain\ntokens. An attacker could possibly use this issue to obtain authentication\ntokens used in REST requests. (CVE-2014-4615)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"neutron","version":"1:2014.1.2-0ubuntu1.1","description":"OpenStack Virtual Network Service","is_source":true},{"name":"neutron-common","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-dhcp-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-l3-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-lbaas-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-metadata-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-metering-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-bigswitch","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-bigswitch-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-brocade","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-cisco","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-hyperv","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-ibm","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-ibm-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-linuxbridge","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-linuxbridge-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-metaplugin","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-metering-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-midonet","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-ml2","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-mlnx","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-mlnx-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-nec","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-nec-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-nicira","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-oneconvergence","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-oneconvergence-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-openflow-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-openvswitch","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-openvswitch-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-plumgrid","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-ryu","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-ryu-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-vmware","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-vpn-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-server","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"neutron-vpn-agent","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"},{"name":"python-neutron","version":"1:2014.1.2-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1.2-0ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3555","CVE-2014-4615"]}]},{"id":"CVE-2014-1419","published":"2014-07-22T17:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in the power policy functions in policy-funcs in\nacpi-support before 0.142 allows local users to gain privileges via\nunspecified vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"policy-funcs was dropped in acpi-support 0.142"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2297-1","https://www.cve.org/CVERecord?id=CVE-2014-1419"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/acpi-support/+bug/1340812"],"patches":{"acpi-support":[]},"tags":{},"packages":[{"name":"acpi-support","source":"https://ubuntu.com/security/cve?package=acpi-support","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=acpi-support","debian":"https://tracker.debian.org/pkg/acpi-support","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.140.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.142","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [0.142]]","component":null,"pocket":"security"}]}],"notices_ids":["USN-2297-1"],"notices":[{"id":"USN-2297-1","title":"acpi-support vulnerability","summary":"The system could be made to run programs as an administrator.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-07-22T17:07:10.278606","description":"CESG discovered that acpi-support incorrectly handled certain privileged\noperations when checking for power management daemons. A local attacker\ncould use this flaw to execute arbitrary code and elevate privileges to\nroot.\n","is_hidden":false,"release_packages":{"precise":[{"name":"acpi-support","version":"0.140.2","description":"scripts for handling many ACPI events","is_source":true},{"name":"acpi-support","version":"0.140.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/acpi-support","version_link":"https://launchpad.net/ubuntu/+source/acpi-support/0.140.2"}]},"type":"USN","cves_ids":["CVE-2014-1419"]}]},{"id":"CVE-2014-5022","published":"2014-07-22T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x\nbefore 7.29 allows remote attackers to inject arbitrary web script or HTML\nvia vectors involving forms with an Ajax-enabled textfield and a file\nfield.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2014-003","http://www.debian.org/security/2014/dsa-2983","https://www.cve.org/CVERecord?id=CVE-2014-5022"],"bugs":[""],"patches":{"drupal7":[]},"tags":{},"packages":[{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"vivid","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.29","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5021","published":"2014-07-22T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x\nbefore 6.32 and possibly 7.x before 7.29 allows remote authenticated users\nwith the \"administer taxonomy\" permission to inject arbitrary web script or\nHTML via an option group label.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2014-003","http://www.debian.org/security/2014/dsa-2983","https://www.cve.org/CVERecord?id=CVE-2014-5021"],"bugs":[""],"patches":{"drupal6":[],"drupal7":[]},"tags":{},"packages":[{"name":"drupal6","source":"https://ubuntu.com/security/cve?package=drupal6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=drupal6","debian":"https://tracker.debian.org/pkg/drupal6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.32","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"vivid","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.29","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5020","published":"2014-07-22T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe File module in Drupal 7.x before 7.29 does not properly check\npermissions to view files, which allows remote authenticated users with\ncertain permissions to bypass intended restrictions and read files by\nattaching the file to content with a file field.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2014-003","http://www.debian.org/security/2014/dsa-2983","https://www.cve.org/CVERecord?id=CVE-2014-5020"],"bugs":[""],"patches":{"drupal7":[]},"tags":{},"packages":[{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"artful","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.29","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.32-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":65080,"limit":20,"total_results":79316}