{"cves":[{"id":"CVE-2013-7386","published":"2014-06-02T15:55:00","updated_at":"2025-07-17T16:42:37.676184+00:00","description":"\nFormat string vulnerability in the PROJECT::write_account_file function in\nclient/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to\ncause a denial of service (crash) or possibly execute arbitrary code via\nformat string specifiers in the gui_urls item in an account file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git;a=commitdiff;h=99258dcecba8ef36e1ce0fd6e0dacffe53613ac9","https://bugzilla.redhat.com/show_bug.cgi?id=957795","http://www.openwall.com/lists/oss-security/2013/04/28/3","http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125128.html","http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125125.html","https://www.cve.org/CVERecord?id=CVE-2013-7386"],"bugs":[""],"patches":{"boinc":[]},"tags":{},"packages":[{"name":"boinc","source":"https://ubuntu.com/security/cve?package=boinc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boinc","debian":"https://tracker.debian.org/pkg/boinc","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"7.2.7+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.1.10+dfsg-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2298","published":"2014-06-02T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in the XML parser in BOINC 7.x allow\nattackers to have unspecified impact via a crafted XML file, related to the\nscheduler.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git;a=commitdiff;h=2fea03824925cbcb976f4191f4d8321e41a4d95b","http://www.openwall.com/lists/oss-security/2013/04/28","https://www.cve.org/CVERecord?id=CVE-2013-2298"],"bugs":[""],"patches":{"boinc":["upstream: http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git;a=commitdiff;h=2fea03824925cbcb976f4191f4d8321e41a4d95b"]},"tags":{},"packages":[{"name":"boinc","source":"https://ubuntu.com/security/cve?package=boinc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boinc","debian":"https://tracker.debian.org/pkg/boinc","statuses":[{"release_codename":"vivid","status":"not-affected","description":"7.2.42+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"7.2.7+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.65+dfsg-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.2.42+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.2.42+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.2.42+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.2.42+dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.2.42+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [7.2.42+dfsg-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2019","published":"2014-06-02T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote\nattackers to have unspecified impact via multiple file_signature elements.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git;a=commitdiff;h=9a4140ae30a72e5175f3f31646d91f2d58df7156","http://thread.gmane.org/gmane.comp.distributed.boinc.user/3741","https://www.cve.org/CVERecord?id=CVE-2013-2019"],"bugs":[""],"patches":{"boinc":["upstream: http://boinc.berkeley.edu/dl/patch_2a6f65cf.diff"]},"tags":{},"packages":[{"name":"boinc","source":"https://ubuntu.com/security/cve?package=boinc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boinc","debian":"https://tracker.debian.org/pkg/boinc","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"7.0.27+dfsg-5ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"7.0.27+dfsg-5ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"7.0.27+dfsg-5ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"7.0.27+dfsg-5ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.13.6+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2014","published":"2014-06-02T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Identity (Keystone) before 2013.1 allows remote attackers to\ncause a denial of service (memory consumption and crash) via multiple long\nrequests.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Upstream is not backporting the sizelimit middleware to Folsom or\nEssex because it is too intrusive\nrequires keystone to be directly exposed to incoming POST messages\nand not protected by a proxy\nsee https://bugs.launchpad.net/ossn/+bug/1155566/comments/14 for\nmitigation strategies"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-2014"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=708515","https://bugs.launchpad.net/ossn/+bug/1155566","https://bugs.launchpad.net/keystone/+bug/1098177"],"patches":{"keystone":[]},"tags":{},"packages":[{"name":"keystone","source":"https://ubuntu.com/security/cve?package=keystone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=keystone","debian":"https://tracker.debian.org/pkg/keystone","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2013.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1818","published":"2014-06-02T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmaintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote\nattackers to read arbitrary files via unspecified vectors.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"per Kurt, only 1.20.2 affected; also, requires register_globals"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.wikimedia.org/show_bug.cgi?id=45355","http://www.openwall.com/lists/oss-security/2013/03/05/4","https://www.cve.org/CVERecord?id=CVE-2013-1818"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"hardy","status":"not-affected","description":"1:1.11.2-2ubuntu0.7","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1:1.15.1-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1:1.15.5-3build1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1:1.15.5-7","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1:1.19.2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.20.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-5391","published":"2014-06-02T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSession fixation vulnerability in Special:UserLogin in MediaWiki before\n1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote\nattackers to hijack web sessions via the session_id.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.wikimedia.org/show_bug.cgi?id=40995","http://xforce.iss.net/xforce/xfdb/83008","http://lists.wikimedia.org/pipermail/mediawiki-announce/2012-November/000122.html","http://lists.fedoraproject.org/pipermail/package-announce/2013-March/100845.html","http://lists.fedoraproject.org/pipermail/package-announce/2013-March/100843.html","http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098975.html","https://www.cve.org/CVERecord?id=CVE-2012-5391"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=694998"],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1:1.19.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.19.3-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-5280","published":"2014-06-02T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in BOINC 6.13.x allow remote\nattackers to cause a denial of service (crash) via a long trickle-up to (1)\nclient/cs_trickle.cpp or (2) db/db_base.cpp.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream, only 6.x affected"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git;a=commitdiff;h=ae04b50a71f3e96ee1bc59b76fca97cf0fe976f7","http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git;a=commitdiff;h=5b04b249db166ec38c1ee99a9eadcaa300c0f454","http://www.openwall.com/lists/oss-security/2013/04/28/3","https://www.cve.org/CVERecord?id=CVE-2011-5280"],"bugs":[""],"patches":{"boinc":[]},"tags":{"boinc":["stack-protector"]},"packages":[{"name":"boinc","source":"https://ubuntu.com/security/cve?package=boinc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boinc","debian":"https://tracker.debian.org/pkg/boinc","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"7.0.27+dfsg-5ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6433","published":"2014-06-02T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration in the Red Hat openstack-neutron package before\n2013.2.3-7 does not properly set a configuration file for rootwrap, which\nallows remote attackers to gain privileges via a crafted configuration\nfile.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"medium because while the issue is privilege escalation, it requires\nanother flaw to exploit\nthe Ubuntu 14.10 1:2014.2~b1-0ubuntu3 upload mistakenly references\nCVE-2013-1068"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1039812","http://rhn.redhat.com/errata/RHSA-2014-0516.html","https://wiki.openstack.org/wiki/Packager/Rootwrap","https://ubuntu.com/security/notices/USN-2255-1","https://www.cve.org/CVERecord?id=CVE-2013-6433"],"bugs":["https://launchpad.net/bugs/1185019","https://bugzilla.redhat.com/show_bug.cgi?id=1039812"],"patches":{"quantum":[],"neutron":[]},"tags":{},"packages":[{"name":"neutron","source":"https://ubuntu.com/security/cve?package=neutron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neutron","debian":"https://tracker.debian.org/pkg/neutron","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:2013.2.3-0ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:2014.1-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"quantum","source":"https://ubuntu.com/security/cve?package=quantum","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=quantum","debian":"https://tracker.debian.org/pkg/quantum","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2255-1"],"notices":[{"id":"USN-2255-1","title":"OpenStack Neutron vulnerabilities","summary":"Several security issues were fixed in OpenStack Neutron.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-25T21:37:58.916407","description":"Darragh O'Reilly discovered that the Ubuntu packaging for OpenStack Neutron\ndid not properly set up its sudo configuration. If a different flaw was\nfound in OpenStack Neutron, this vulnerability could be used to escalate\nprivileges. (CVE-2013-6433)\n\nStephen Ma and Christoph Thiel discovered that the openvswitch-agent in\nOpenStack Neutron did not properly perform input validation when creating\nsecurity group rules when specifying --remote-ip-prefix. A remote\nauthenticated attacker could exploit this to prevent application of\nadditional rules. (CVE-2014-0187)\n\nThiago Martins discovered that OpenStack Neutron would inappropriately\napply SNAT rules to IPv6 subnets when using the L3-agent. A remote\nauthenticated attacker could exploit this to prevent floating IPv4\naddresses from being attached throughout the cloud. (CVE-2014-4167)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"neutron","version":"1:2013.2.3-0ubuntu1.5","description":"OpenStack Virtual Network Service","is_source":true},{"name":"python-neutron","version":"1:2013.2.3-0ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2013.2.3-0ubuntu1.5"}],"trusty":[{"name":"neutron","version":"1:2014.1-0ubuntu1.3","description":"OpenStack Virtual Network Service","is_source":true},{"name":"neutron-common","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-dhcp-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-l3-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-lbaas-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-metadata-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-metering-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-bigswitch","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-bigswitch-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-brocade","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-cisco","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-hyperv","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-ibm","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-ibm-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-linuxbridge","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-linuxbridge-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-metaplugin","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-metering-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-midonet","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-ml2","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-mlnx","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-mlnx-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-nec","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-nec-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-nicira","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-oneconvergence","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-oneconvergence-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-openflow-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-openvswitch","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-openvswitch-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-plumgrid","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-ryu","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-ryu-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-vmware","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-plugin-vpn-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-server","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"neutron-vpn-agent","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"},{"name":"python-neutron","version":"1:2014.1-0ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/1:2014.1-0ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-6433","CVE-2014-0187","CVE-2014-4167"]}]},{"id":"CVE-2014-3925","published":"2014-06-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL)\n5 produces an archive with an fstab file potentially containing cleartext\npasswords, and lacks a warning about reviewing this archive to detect\nincluded passwords, which might allow remote attackers to obtain sensitive\ninformation by leveraging access to a technical-support data stream.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Fixed upstream in the 3.2 release"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://openwall.com/lists/oss-security/2014/05/30/3","http://openwall.com/lists/oss-security/2014/05/29/6","https://ubuntu.com/security/notices/USN-2845-1","https://www.cve.org/CVERecord?id=CVE-2014-3925"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1102633"],"patches":{"sosreport":["upstream: https://github.com/sosreport/sos/commit/7b46d34654735d925bcb2a3e4b27b65dce994519"]},"tags":{},"packages":[{"name":"sosreport","source":"https://ubuntu.com/security/cve?package=sosreport","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sosreport","debian":"https://tracker.debian.org/pkg/sosreport","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.2-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2845-1"],"notices":[{"id":"USN-2845-1","title":"SoS vulnerabilities","summary":"sosreport could be made to expose sensitive information or overwrite files\nas the administrator.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-12-18T03:39:01.461560","description":"Dolev Farhi discovered an information disclosure issue in SoS. If the\n/etc/fstab file contained passwords, the passwords were included in the\nSoS report. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-3925)\n\nMateusz Guzik discovered that SoS incorrectly handled temporary files. A\nlocal attacker could possibly use this issue to overwrite arbitrary files\nor gain access to temporary file contents containing sensitive system\ninformation. (CVE-2015-7529)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"sosreport","version":"3.1-1ubuntu2.2","description":"Set of tools to gather troubleshooting data from a system","is_source":true},{"name":"sosreport","version":"3.1-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sosreport","version_link":"https://launchpad.net/ubuntu/+source/sosreport/3.1-1ubuntu2.2","pocket":"security"}],"vivid":[{"name":"sosreport","version":"3.2-2ubuntu0.1","description":"Set of tools to gather troubleshooting data from a system","is_source":true},{"name":"sosreport","version":"3.2-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sosreport","version_link":"https://launchpad.net/ubuntu/+source/sosreport/3.2-2ubuntu0.1"}],"wily":[{"name":"sosreport","version":"3.2-2ubuntu1.1","description":"Set of tools to gather troubleshooting data from a system","is_source":true},{"name":"sosreport","version":"3.2-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sosreport","version_link":"https://launchpad.net/ubuntu/+source/sosreport/3.2-2ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2014-3925","CVE-2015-7529"]}]},{"id":"CVE-2014-3466","published":"2014-06-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the read_server_hello function in lib/gnutls_handshake.c\nin GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows\nremote servers to cause a denial of service (memory corruption) or possibly\nexecute arbitrary code via a long session id in a ServerHello message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.gnutls.org/security.html#GNUTLS-SA-2014-3","https://ubuntu.com/security/notices/USN-2229-1","https://www.cve.org/CVERecord?id=CVE-2014-3466"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3466"],"patches":{"gnutls26":["upstream: https://www.gitorious.org/gnutls/gnutls/commit/89238044ade02c4d80e334ab74056ef28599663d"],"gnutls28":["upstream: https://www.gitorious.org/gnutls/gnutls/commit/688ea6428a432c39203d00acd1af0e7684e5ddfd","upstream: https://www.gitorious.org/gnutls/gnutls/commit/a7be326f0e33cf7ce52b36474c157f782d9ca977"]},"tags":{},"packages":[{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"lucid","status":"released","description":"2.8.5-2ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.12.14-5ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.12.23-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.12.23-12ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2.12.23-15ubuntu2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gnutls28","source":"https://ubuntu.com/security/cve?package=gnutls28","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls28","debian":"https://tracker.debian.org/pkg/gnutls28","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.0.11-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.2.11-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.25,3.2.15,3.3.4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.2.15-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.2.15-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2229-1"],"notices":[{"id":"USN-2229-1","title":"GnuTLS vulnerability","summary":"GnuTLS could be made to crash or run programs if it connected to a\nmalicious server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-02T13:17:23.385405","description":"Joonas Kuorilehto discovered that GnuTLS incorrectly handled Server Hello\nmessages. A malicious remote server or a machine-in-the-middle could use this\nissue to cause GnuTLS to crash, resulting in a denial of service, or\npossibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"gnutls26","version":"2.8.5-2ubuntu0.6","description":"GNU TLS library","is_source":true},{"name":"libgnutls26","version":"2.8.5-2ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.8.5-2ubuntu0.6"}],"precise":[{"name":"gnutls26","version":"2.12.14-5ubuntu3.8","description":"GNU TLS library","is_source":true},{"name":"libgnutls26","version":"2.12.14-5ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.14-5ubuntu3.8"}],"saucy":[{"name":"gnutls26","version":"2.12.23-1ubuntu4.3","description":"GNU TLS library","is_source":true},{"name":"libgnutls26","version":"2.12.23-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-1ubuntu4.3"}],"trusty":[{"name":"gnutls26","version":"2.12.23-12ubuntu2.1","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.0.11+really2.12.23-12ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.1","pocket":"security"},{"name":"gnutls26-doc","version":"2.12.23-12ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.1","pocket":"security"},{"name":"libgnutls-dev","version":"2.12.23-12ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.1","pocket":"security"},{"name":"libgnutls-openssl27","version":"2.12.23-12ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.1","pocket":"security"},{"name":"libgnutls26","version":"2.12.23-12ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.1","pocket":"security"},{"name":"libgnutlsxx27","version":"2.12.23-12ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3466"]}]},{"id":"CVE-2014-0238","published":"2014-06-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cdf_read_property_info function in cdf.c in the Fileinfo component in\nPHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause\na denial of service (infinite loop or out-of-bounds memory access) via a\nvector that (1) has zero length or (2) is too long.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.php.net/ChangeLog-5.php","https://ubuntu.com/security/notices/USN-2254-1","https://www.cve.org/CVERecord?id=CVE-2014-0238"],"bugs":["https://bugs.php.net/bug.php?id=67327","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0238"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=22736b7c56d678f142d5dd21f4996e5819507a2b","other: https://github.com/file/file/commit/f97486ef5dc3e8735440edc4fc8808c63e1a3ef0"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.25","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.12","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.3+dfsg-1ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.13","component":null,"pocket":"security"}]}],"notices_ids":["USN-2254-1"],"notices":[{"id":"USN-2254-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-23T12:05:29.233819","description":"Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM)\nset incorrect permissions on the UNIX socket. A local attacker could use\nthis issue to possibly elevate their privileges. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185)\n\nFrancisco Alonso discovered that the PHP Fileinfo component incorrectly\nhandled certain CDF documents. A remote attacker could use this issue to\ncause PHP to hang or crash, resulting in a denial of service.\n(CVE-2014-0237, CVE-2014-0238)\n\nStefan Esser discovered that PHP incorrectly handled DNS TXT records. A\nremote attacker could use this issue to cause PHP to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2014-4049)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.25","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25"},{"name":"php5-cli","version":"5.3.2-1ubuntu4.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25"}],"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.12","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"}],"saucy":[{"name":"php5","version":"5.5.3+dfsg-1ubuntu2.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"},{"name":"php5-cgi","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"},{"name":"php5-cli","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"},{"name":"php5-fpm","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0185","CVE-2014-0237","CVE-2014-0238","CVE-2014-4049"]}]},{"id":"CVE-2014-0237","published":"2014-06-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe cdf_unpack_summary_info function in cdf.c in the Fileinfo component in\nPHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause\na denial of service (performance degradation) by triggering many\nfile_printf calls.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.php.net/ChangeLog-5.php","https://ubuntu.com/security/notices/USN-2254-1","https://www.cve.org/CVERecord?id=CVE-2014-0237"],"bugs":["https://bugs.php.net/bug.php?id=67328","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0237"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commit;h=68ce2d0ea6da79b12a365e375e1c2ce882c77480","other: https://github.com/file/file/commit/b8acc83781d5a24cc5101e525d15efe0482c280d"]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"lucid","status":"released","description":"5.3.2-1ubuntu4.25","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.3.10-1ubuntu3.12","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.3+dfsg-1ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.9+dfsg-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.13","component":null,"pocket":"security"}]}],"notices_ids":["USN-2254-1"],"notices":[{"id":"USN-2254-1","title":"PHP vulnerabilities","summary":"Several security issues were fixed in PHP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-23T12:05:29.233819","description":"Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM)\nset incorrect permissions on the UNIX socket. A local attacker could use\nthis issue to possibly elevate their privileges. This issue only affected\nUbuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185)\n\nFrancisco Alonso discovered that the PHP Fileinfo component incorrectly\nhandled certain CDF documents. A remote attacker could use this issue to\ncause PHP to hang or crash, resulting in a denial of service.\n(CVE-2014-0237, CVE-2014-0238)\n\nStefan Esser discovered that PHP incorrectly handled DNS TXT records. A\nremote attacker could use this issue to cause PHP to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. (CVE-2014-4049)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"php5","version":"5.3.2-1ubuntu4.25","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.2-1ubuntu4.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25"},{"name":"php5-cgi","version":"5.3.2-1ubuntu4.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25"},{"name":"php5-cli","version":"5.3.2-1ubuntu4.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25"}],"precise":[{"name":"php5","version":"5.3.10-1ubuntu3.12","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"},{"name":"php5-cgi","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"},{"name":"php5-cli","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"},{"name":"php5-fpm","version":"5.3.10-1ubuntu3.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12"}],"saucy":[{"name":"php5","version":"5.5.3+dfsg-1ubuntu2.4","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"},{"name":"php5-cgi","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"},{"name":"php5-cli","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"},{"name":"php5-fpm","version":"5.5.3+dfsg-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4"}],"trusty":[{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.1","description":"HTML-embedded scripting language interpreter","is_source":true},{"name":"libapache2-mod-php5","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"libapache2-mod-php5filter","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"libphp5-embed","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php-pear","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-cgi","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-cli","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-common","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-curl","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-dev","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-enchant","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-fpm","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-gd","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-gmp","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-intl","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-ldap","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-mysql","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-mysqlnd","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-odbc","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-pgsql","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-pspell","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-readline","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-recode","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-snmp","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-sqlite","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-sybase","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-tidy","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-xmlrpc","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"},{"name":"php5-xsl","version":"5.5.9+dfsg-1ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/php5","version_link":"https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0185","CVE-2014-0237","CVE-2014-0238","CVE-2014-4049"]}]},{"id":"CVE-2014-3793","published":"2014-05-31T11:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nVMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x\nbefore 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through\n5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain\nguest OS privileges or cause a denial of service (kernel NULL pointer\ndereference and guest OS crash) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.vmware.com/security/advisories/VMSA-2014-0005.html","https://www.cve.org/CVERecord?id=CVE-2014-3793"],"bugs":[""],"patches":{"vmware-view-client":[]},"tags":{},"packages":[{"name":"vmware-view-client","source":"https://ubuntu.com/security/cve?package=vmware-view-client","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vmware-view-client","debian":"https://tracker.debian.org/pkg/vmware-view-client","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [Windows only]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0095","published":"2014-05-31T11:17:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\njava/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x\nbefore 8.0.4 allows remote attackers to cause a denial of service (thread\nconsumption) by using a \"Content-Length: 0\" AJP request to trigger a hang\nin request processing.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-0095"],"bugs":[""],"patches":{"tomcat8":[]},"tags":{},"packages":[{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.5-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"8.0.26-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0119","published":"2014-05-31T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Tomcat before 6.0.40, 7.x before 7.0.54, and 8.x before 8.0.6 does\nnot properly constrain the class loader that accesses the XML parser used\nwith an XSLT stylesheet, which allows remote attackers to (1) read\narbitrary files via a crafted web application that provides an XML external\nentity declaration in conjunction with an entity reference, related to an\nXML External Entity (XXE) issue, or (2) read files associated with\ndifferent web applications on a single Tomcat instance via a crafted web\napplication.","ubuntu_description":"\nIt was discovered that the Tomcat XML parser incorrectly handled XML\nExternal Entities (XXE). A remote attacker could possibly use this issue to\nread arbitrary files. This issue only affected Ubuntu 14.04 LTS.","notes":[{"author":"mdeslaur","note":"patch is intrusive"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2654-1","https://www.cve.org/CVERecord?id=CVE-2014-0119"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/tomcat7/+bug/1449975"],"patches":{"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1589640","upstream: http://svn.apache.org/viewvc?view=revision&revision=1593815","upstream: http://svn.apache.org/viewvc?view=revision&revision=1593821"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1589763","upstream: http://svn.apache.org/viewvc?view=revision&revision=1589851","upstream: http://svn.apache.org/viewvc?view=revision&revision=1588199","upstream: http://svn.apache.org/viewvc?view=revision&revision=1589997","upstream: http://svn.apache.org/viewvc?view=revision&revision=1590028","upstream: http://svn.apache.org/viewvc?view=revision&revision=1590036","vendor: https://git.centos.org/blob/rpms!tomcat.git/f90819793e4da6c0cc3e7c19d29b48710e29d05b/SOURCES!tomcat-7.0.42-CVE-2014-0119.patch"],"tomcat8":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6.0.39-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"artful","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.0.52-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.5-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2654-1"],"notices":[{"id":"USN-2654-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2015-06-25T12:32:34.216882","description":"It was discovered that the Tomcat XML parser incorrectly handled XML\nExternal Entities (XXE). A remote attacker could possibly use this issue to\nread arbitrary files. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2014-0119)\n\nIt was discovered that Tomcat incorrectly handled data with malformed\nchunked transfer coding. A remote attacker could possibly use this issue to\nconduct HTTP request smuggling attacks, or cause Tomcat to consume\nresources, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2014-0227)\n\nIt was discovered that Tomcat incorrectly handled HTTP responses occurring\nbefore the entire request body was finished being read. A remote attacker\ncould possibly use this issue to cause a limited denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2014-0230)\n\nIt was discovered that the Tomcat Expression Language (EL) implementation\nincorrectly handled accessible interfaces implemented by inaccessible\nclasses. An attacker could possibly use this issue to bypass a\nSecurityManager protection mechanism. (CVE-2014-7810)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tomcat7","version":"7.0.52-1ubuntu0.3","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.0-java","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"libservlet3.0-java-doc","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"libtomcat7-java","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"tomcat7","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"tomcat7-admin","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"tomcat7-common","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"tomcat7-docs","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"tomcat7-examples","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"},{"name":"tomcat7-user","version":"7.0.52-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.3","pocket":"security"}],"utopic":[{"name":"tomcat7","version":"7.0.55-1ubuntu0.2","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat7-java","version":"7.0.55-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.55-1ubuntu0.2"}],"vivid":[{"name":"tomcat7","version":"7.0.56-2ubuntu0.1","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat7-java","version":"7.0.56-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.56-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2014-0119","CVE-2014-0227","CVE-2014-0230","CVE-2014-7810"]}]},{"id":"CVE-2014-0099","published":"2014-05-31T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache\nTomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when\noperated behind a reverse proxy, allows remote attackers to conduct HTTP\nrequest smuggling attacks via a crafted Content-Length HTTP header.","ubuntu_description":"\nIt was discovered that Tomcat incorrectly handled certain Content-Length\nheaders. A remote attacker could use this flaw in configurations where\nTomcat is behind a reverse proxy to perform HTTP request smuggling attacks.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2302-1","https://www.cve.org/CVERecord?id=CVE-2014-0099"],"bugs":[""],"patches":{"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1580473"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1578814"],"tomcat8":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"vivid","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6.0.35-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6.0.39-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"artful","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.0.52-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.5-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2302-1"],"notices":[{"id":"USN-2302-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-07-30T16:37:59.391694","description":"David Jorm discovered that Tomcat incorrectly handled certain requests\nsubmitted using chunked transfer encoding. A remote attacker could use this\nflaw to cause the Tomcat server to consume resources, resulting in a denial\nof service. (CVE-2014-0075)\n\nIt was discovered that Tomcat did not properly restrict XSLT stylesheets.\nAn attacker could use this issue with a crafted web application to bypass\nsecurity-manager restrictions and read arbitrary files. (CVE-2014-0096)\n\nIt was discovered that Tomcat incorrectly handled certain Content-Length\nheaders. A remote attacker could use this flaw in configurations where\nTomcat is behind a reverse proxy to perform HTTP request smuggling attacks.\n(CVE-2014-0099)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tomcat6","version":"6.0.24-2ubuntu1.16","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.24-2ubuntu1.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.24-2ubuntu1.16"}],"precise":[{"name":"tomcat6","version":"6.0.35-1ubuntu3.5","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.35-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.35-1ubuntu3.5"}],"trusty":[{"name":"tomcat7","version":"7.0.52-1ubuntu0.1","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.0-java","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"libservlet3.0-java-doc","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"libtomcat7-java","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-admin","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-common","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-docs","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-examples","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-user","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0075","CVE-2014-0096","CVE-2014-0099"]}]},{"id":"CVE-2014-0096","published":"2014-05-31T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\njava/org/apache/catalina/servlets/DefaultServlet.java in the default\nservlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before\n8.0.4 does not properly restrict XSLT stylesheets, which allows remote\nattackers to bypass security-manager restrictions and read arbitrary files\nvia a crafted web application that provides an XML external entity\ndeclaration in conjunction with an entity reference, related to an XML\nExternal Entity (XXE) issue.","ubuntu_description":"\nIt was discovered that Tomcat did not properly restrict XSLT stylesheets.\nAn attacker could use this issue with a crafted web application to bypass\nsecurity-manager restrictions and read arbitrary files.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2302-1","https://www.cve.org/CVERecord?id=CVE-2014-0096"],"bugs":[""],"patches":{"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1585853"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1578637","upstream: http://svn.apache.org/viewvc?view=revision&revision=1578655"],"tomcat8":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6.0.35-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6.0.39-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"artful","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.0.52-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.5-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2302-1"],"notices":[{"id":"USN-2302-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-07-30T16:37:59.391694","description":"David Jorm discovered that Tomcat incorrectly handled certain requests\nsubmitted using chunked transfer encoding. A remote attacker could use this\nflaw to cause the Tomcat server to consume resources, resulting in a denial\nof service. (CVE-2014-0075)\n\nIt was discovered that Tomcat did not properly restrict XSLT stylesheets.\nAn attacker could use this issue with a crafted web application to bypass\nsecurity-manager restrictions and read arbitrary files. (CVE-2014-0096)\n\nIt was discovered that Tomcat incorrectly handled certain Content-Length\nheaders. A remote attacker could use this flaw in configurations where\nTomcat is behind a reverse proxy to perform HTTP request smuggling attacks.\n(CVE-2014-0099)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tomcat6","version":"6.0.24-2ubuntu1.16","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.24-2ubuntu1.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.24-2ubuntu1.16"}],"precise":[{"name":"tomcat6","version":"6.0.35-1ubuntu3.5","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.35-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.35-1ubuntu3.5"}],"trusty":[{"name":"tomcat7","version":"7.0.52-1ubuntu0.1","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.0-java","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"libservlet3.0-java-doc","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"libtomcat7-java","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-admin","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-common","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-docs","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-examples","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-user","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0075","CVE-2014-0096","CVE-2014-0099"]}]},{"id":"CVE-2014-0075","published":"2014-05-31T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the parseChunkHeader function in\njava/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache\nTomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remote\nattackers to cause a denial of service (resource consumption) via a\nmalformed chunk size in chunked transfer coding of a request during the\nstreaming of data.","ubuntu_description":"\nDavid Jorm discovered that Tomcat incorrectly handled certain requests\nsubmitted using chunked transfer encoding. A remote attacker could use this\nflaw to cause the Tomcat server to consume resources, resulting in a denial\nof service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2302-1","https://www.cve.org/CVERecord?id=CVE-2014-0075"],"bugs":[""],"patches":{"tomcat6":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1579262"],"tomcat7":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1578341"],"tomcat8":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"vivid","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.24-2ubuntu1.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6.0.35-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6.0.39-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"6.0.41-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"vivid","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.0.52-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.0.53-1","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"vivid","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.5-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"8.0.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2302-1"],"notices":[{"id":"USN-2302-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-07-30T16:37:59.391694","description":"David Jorm discovered that Tomcat incorrectly handled certain requests\nsubmitted using chunked transfer encoding. A remote attacker could use this\nflaw to cause the Tomcat server to consume resources, resulting in a denial\nof service. (CVE-2014-0075)\n\nIt was discovered that Tomcat did not properly restrict XSLT stylesheets.\nAn attacker could use this issue with a crafted web application to bypass\nsecurity-manager restrictions and read arbitrary files. (CVE-2014-0096)\n\nIt was discovered that Tomcat incorrectly handled certain Content-Length\nheaders. A remote attacker could use this flaw in configurations where\nTomcat is behind a reverse proxy to perform HTTP request smuggling attacks.\n(CVE-2014-0099)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"tomcat6","version":"6.0.24-2ubuntu1.16","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.24-2ubuntu1.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.24-2ubuntu1.16"}],"precise":[{"name":"tomcat6","version":"6.0.35-1ubuntu3.5","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat6-java","version":"6.0.35-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat6","version_link":"https://launchpad.net/ubuntu/+source/tomcat6/6.0.35-1ubuntu3.5"}],"trusty":[{"name":"tomcat7","version":"7.0.52-1ubuntu0.1","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.0-java","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"libservlet3.0-java-doc","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"libtomcat7-java","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-admin","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-common","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-docs","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-examples","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"},{"name":"tomcat7-user","version":"7.0.52-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0075","CVE-2014-0096","CVE-2014-0099"]}]},{"id":"CVE-2014-3227","published":"2014-05-30T18:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ndpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the\npatch program to be compliant with a need for the \"C-style encoded\nfilenames\" feature, but is supported in environments with noncompliant\npatch programs, which triggers an interaction error that allows remote\nattackers to conduct directory traversal attacks and modify files outside\nof the intended directories via a crafted source package. NOTE: this\nvulnerability exists because of reliance on unrealistic constraints on the\nbehavior of an external program.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746306","http://openwall.com/lists/oss-security/2014/05/29/16","http://openwall.com/lists/oss-security/2014/04/29/4","https://ubuntu.com/security/notices/USN-2183-2","https://www.cve.org/CVERecord?id=CVE-2014-3227"],"bugs":[""],"patches":{"dpkg":[]},"tags":{},"packages":[{"name":"dpkg","source":"https://ubuntu.com/security/cve?package=dpkg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dpkg","debian":"https://tracker.debian.org/pkg/dpkg","statuses":[{"release_codename":"trusty","status":"released","description":"1.16.12ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.15.5.6ubuntu4.8","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.16.1.2ubuntu7.4","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.16.7ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5919","published":"2014-05-30T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSuricata before 1.4.6 allows remote attackers to cause a denial of service\n(crash) via a malformed SSL record.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://suricata-ids.org/2013/09/24/suricata-1-4-6-released/","http://xforce.iss.net/xforce/xfdb/87492","http://secunia.com/advisories/54968","https://www.cve.org/CVERecord?id=CVE-2013-5919"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.4.7-1ubuntu1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":65380,"limit":20,"total_results":79316}