{"cves":[{"id":"CVE-2013-0345","published":"2014-05-08T14:29:00","updated_at":"2025-08-04T19:24:19.235787+00:00","description":"\nvarnish 3.0.3 uses world-readable permissions for the /var/log/varnish/\ndirectory and the log files in the directory, which allows local users to\nobtain sensitive information by reading the files. NOTE: some of these\ndetails are obtained from third party information.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"/var/log/varnish is 750 in Ubuntu 11.10 and higher"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-0345"],"bugs":[""],"patches":{"varnish":[]},"tags":{},"packages":[{"name":"varnish","source":"https://ubuntu.com/security/cve?package=varnish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=varnish","debian":"https://tracker.debian.org/pkg/varnish","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3424","published":"2014-05-08T10:55:00","updated_at":"2026-05-22T18:23:41.619518+00:00","description":"\nlisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to\noverwrite arbitrary files via a symlink attack on a /tmp/tramp.#####\ntemporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00060.html","http://openwall.com/lists/oss-security/2014/05/07/7","http://debbugs.gnu.org/cgi/bugreport.cgi?bug=17428#8","https://www.cve.org/CVERecord?id=CVE-2014-3424"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747100"],"patches":{"xemacs21":[],"xemacs21-packages":[],"emacs22":[],"emacs-snapshot":[],"emacs23":["upstream: http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00060.html"],"emacs24":["upstream: http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00060.html"],"emacs25":[]},"tags":{"emacs23":["hardlink-restriction","symlink-restriction"],"emacs24":["hardlink-restriction","symlink-restriction"]},"packages":[{"name":"emacs-snapshot","source":"https://ubuntu.com/security/cve?package=emacs-snapshot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs-snapshot","debian":"https://tracker.debian.org/pkg/emacs-snapshot","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs22","source":"https://ubuntu.com/security/cve?package=emacs22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs22","debian":"https://tracker.debian.org/pkg/emacs22","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs23","source":"https://ubuntu.com/security/cve?package=emacs23","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs23","debian":"https://tracker.debian.org/pkg/emacs23","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"emacs24","source":"https://ubuntu.com/security/cve?package=emacs24","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs24","debian":"https://tracker.debian.org/pkg/emacs24","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.3+1-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"24.5+1-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"24.5+1-8ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"emacs25","source":"https://ubuntu.com/security/cve?package=emacs25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs25","debian":"https://tracker.debian.org/pkg/emacs25","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xemacs21","source":"https://ubuntu.com/security/cve?package=xemacs21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21","debian":"https://tracker.debian.org/pkg/xemacs21","statuses":[{"release_codename":"artful","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code-not-present]","component":null,"pocket":"security"}]},{"name":"xemacs21-packages","source":"https://ubuntu.com/security/cve?package=xemacs21-packages","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21-packages","debian":"https://tracker.debian.org/pkg/xemacs21-packages","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3423","published":"2014-05-08T10:55:00","updated_at":"2026-05-22T18:22:35.015175+00:00","description":"\nlisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to\noverwrite arbitrary files via a symlink attack on a /tmp/Mosaic.#####\ntemporary file.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Mosiac hard-coded this pid file name, the alternative is dropping\nsupport for Mosiac entirely. Don't be hasty."},{"author":"leosilva","note":"from emacs, they added this line only http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00057.html\nnot-fixed"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00057.html","http://openwall.com/lists/oss-security/2014/05/07/7","http://debbugs.gnu.org/cgi/bugreport.cgi?bug=17428#8","https://www.cve.org/CVERecord?id=CVE-2014-3423"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747100"],"patches":{"xemacs21":[],"xemacs21-packages":[],"emacs22":[],"emacs-snapshot":[],"emacs23":[],"emacs24":[],"emacs25":[]},"tags":{"emacs23":["symlink-restriction","hardlink-restriction"],"emacs24":["symlink-restriction","hardlink-restriction"]},"packages":[{"name":"emacs-snapshot","source":"https://ubuntu.com/security/cve?package=emacs-snapshot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs-snapshot","debian":"https://tracker.debian.org/pkg/emacs-snapshot","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs22","source":"https://ubuntu.com/security/cve?package=emacs22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs22","debian":"https://tracker.debian.org/pkg/emacs22","statuses":[{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs23","source":"https://ubuntu.com/security/cve?package=emacs23","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs23","debian":"https://tracker.debian.org/pkg/emacs23","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"emacs24","source":"https://ubuntu.com/security/cve?package=emacs24","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs24","debian":"https://tracker.debian.org/pkg/emacs24","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.3+1-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"24.5+1-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"24.5+1-8ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"emacs25","source":"https://ubuntu.com/security/cve?package=emacs25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs25","debian":"https://tracker.debian.org/pkg/emacs25","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xemacs21","source":"https://ubuntu.com/security/cve?package=xemacs21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21","debian":"https://tracker.debian.org/pkg/xemacs21","statuses":[{"release_codename":"artful","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code-not-present]","component":null,"pocket":"security"}]},{"name":"xemacs21-packages","source":"https://ubuntu.com/security/cve?package=xemacs21-packages","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21-packages","debian":"https://tracker.debian.org/pkg/xemacs21-packages","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3422","published":"2014-05-08T10:55:00","updated_at":"2026-05-22T18:23:41.619518+00:00","description":"\nlisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users\nto overwrite arbitrary files via a symlink attack on a temporary file under\n/tmp/esrc/.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"The xemacs21-packages code looked very different; the esrc comment\nlooks out-dated. I'm marking these not-affected because it looked safe to me\nbut review by an emacs expert would be welcome."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00056.html","http://openwall.com/lists/oss-security/2014/05/07/7","http://debbugs.gnu.org/cgi/bugreport.cgi?bug=17428#8","https://www.cve.org/CVERecord?id=CVE-2014-3422"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747100"],"patches":{"xemacs21":[],"xemacs21-packages":[],"emacs22":[],"emacs-snapshot":[],"emacs23":["upstream: http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00056.html"],"emacs24":["upstream: http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00056.html"],"emacs25":[]},"tags":{"emacs23":["hardlink-restriction","symlink-restriction"],"emacs24":["hardlink-restriction","symlink-restriction"]},"packages":[{"name":"emacs-snapshot","source":"https://ubuntu.com/security/cve?package=emacs-snapshot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs-snapshot","debian":"https://tracker.debian.org/pkg/emacs-snapshot","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs22","source":"https://ubuntu.com/security/cve?package=emacs22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs22","debian":"https://tracker.debian.org/pkg/emacs22","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs23","source":"https://ubuntu.com/security/cve?package=emacs23","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs23","debian":"https://tracker.debian.org/pkg/emacs23","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"emacs24","source":"https://ubuntu.com/security/cve?package=emacs24","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs24","debian":"https://tracker.debian.org/pkg/emacs24","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.3+1-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"24.5+1-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"24.5+1-8ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"emacs25","source":"https://ubuntu.com/security/cve?package=emacs25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs25","debian":"https://tracker.debian.org/pkg/emacs25","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xemacs21","source":"https://ubuntu.com/security/cve?package=xemacs21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21","debian":"https://tracker.debian.org/pkg/xemacs21","statuses":[{"release_codename":"artful","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code-not-present]","component":null,"pocket":"security"}]},{"name":"xemacs21-packages","source":"https://ubuntu.com/security/cve?package=xemacs21-packages","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21-packages","debian":"https://tracker.debian.org/pkg/xemacs21-packages","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3421","published":"2014-05-08T10:55:00","updated_at":"2026-07-10T06:25:30.206963+00:00","description":"\nlisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to\noverwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm\ntemporary file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00055.html","http://openwall.com/lists/oss-security/2014/05/07/7","http://debbugs.gnu.org/cgi/bugreport.cgi?bug=17428#8","https://www.cve.org/CVERecord?id=CVE-2014-3421"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747100"],"patches":{"xemacs21":[],"xemacs21-packages":[],"emacs22":[],"emacs-snapshot":[],"emacs23":["upstream: http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00055.html"],"emacs24":["upstream: http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00055.html"],"emacs25":[]},"tags":{"xemacs21-packages":["hardlink-restriction","symlink-restriction"],"emacs23":["hardlink-restriction","symlink-restriction"],"emacs24":["hardlink-restriction","symlink-restriction"]},"packages":[{"name":"xemacs21-packages","source":"https://ubuntu.com/security/cve?package=xemacs21-packages","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21-packages","debian":"https://tracker.debian.org/pkg/xemacs21-packages","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]},{"name":"emacs-snapshot","source":"https://ubuntu.com/security/cve?package=emacs-snapshot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs-snapshot","debian":"https://tracker.debian.org/pkg/emacs-snapshot","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs22","source":"https://ubuntu.com/security/cve?package=emacs22","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs22","debian":"https://tracker.debian.org/pkg/emacs22","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs23","source":"https://ubuntu.com/security/cve?package=emacs23","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs23","debian":"https://tracker.debian.org/pkg/emacs23","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs24","source":"https://ubuntu.com/security/cve?package=emacs24","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs24","debian":"https://tracker.debian.org/pkg/emacs24","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.3+1-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"24.5+1-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"24.5+1-8ubuntu2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"emacs25","source":"https://ubuntu.com/security/cve?package=emacs25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs25","debian":"https://tracker.debian.org/pkg/emacs25","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"xemacs21","source":"https://ubuntu.com/security/cve?package=xemacs21","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xemacs21","debian":"https://tracker.debian.org/pkg/xemacs21","statuses":[{"release_codename":"impish","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code-not-present]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3215","published":"2014-05-08T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nseunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions,\nand executes programs in a way that changes the relationship between the\nsetuid system call and the getresuid saved set-user-ID value, which makes\nit easier for local users to gain privileges by leveraging a program that\nmistakenly expected that it could permanently drop privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://openwall.com/lists/oss-security/2014/05/08/1","http://openwall.com/lists/oss-security/2014/04/30/4","http://openwall.com/lists/oss-security/2014/04/29/7","https://www.cve.org/CVERecord?id=CVE-2014-3215"],"bugs":[""],"patches":{"policycoreutils":[]},"tags":{},"packages":[{"name":"policycoreutils","source":"https://ubuntu.com/security/cve?package=policycoreutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=policycoreutils","debian":"https://tracker.debian.org/pkg/policycoreutils","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0116","published":"2014-05-08T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard\ncookiesName value is used, does not properly restrict access to the\ngetClass method, which allows remote attackers to \"manipulate\" the\nClassLoader and modify session state via a crafted request. NOTE: this\nvulnerability exists because of an incomplete fix for CVE-2014-0113.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian: (Struts 2.0.0 through to Struts 2.3.16.2)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://cwiki.apache.org/confluence/display/WW/S2-022","http://struts.apache.org/release/2.3.x/docs/s2-022.html","https://www.cve.org/CVERecord?id=CVE-2014-0116"],"bugs":[""],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0190","published":"2014-05-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause\na denial of service (NULL pointer dereference) via invalid width and height\nvalues in a GIF image.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/04/28","http://lists.qt-project.org/pipermail/announce/2014-April/000045.html","https://ubuntu.com/security/notices/USN-2626-1","https://www.cve.org/CVERecord?id=CVE-2014-0190"],"bugs":["https://bugs.kde.org/show_bug.cgi?id=333404"],"patches":{"qt4-x11":["upstream: https://qt.gitorious.org/qt/qtbase/commit/eb1325047f2697d24e93ebaf924900affc876bc1"],"qtbase-opensource-src":["upstream: http://code.qt.io/cgit/qt/qtbase.git/commit/?id=c5eec579e2fcf3c00cc02ebc0a2fbc347cd595d5"]},"tags":{},"packages":[{"name":"qt4-x11","source":"https://ubuntu.com/security/cve?package=qt4-x11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qt4-x11","debian":"https://tracker.debian.org/pkg/qt4-x11","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:4.8.1-0ubuntu4.9","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4:4.8.6+dfsg-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"4:4.8.6+git49-gbc62005+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu6","component":null,"pocket":"security"}]},{"name":"qtbase-opensource-src","source":"https://ubuntu.com/security/cve?package=qtbase-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtbase-opensource-src","debian":"https://tracker.debian.org/pkg/qtbase-opensource-src","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.2.1+dfsg-1ubuntu14.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.3.0+dfsg-2ubuntu9","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"5.4.1+dfsg-2ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2626-1"],"notices":[{"id":"USN-2626-1","title":"Qt vulnerabilities","summary":"Qt could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2015-06-03T13:33:12.805512","description":"Wolfgang Schenk discovered that Qt incorrectly handled certain malformed\nGIF images. If a user or automated system were tricked into opening a\nspecially crafted GIF image, a remote attacker could use this issue to\ncause Qt to crash, resulting in a denial of service. This issue only\napplied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-0190)\n\nFabian Vogt discovered that Qt incorrectly handled certain malformed BMP\nimages. If a user or automated system were tricked into opening a specially\ncrafted BMP image, a remote attacker could use this issue to cause Qt to\ncrash, resulting in a denial of service. (CVE-2015-0295)\n\nRichard Moore and Fabian Vogt discovered that Qt incorrectly handled\ncertain malformed BMP images. If a user or automated system were tricked\ninto opening a specially crafted BMP image, a remote attacker could use\nthis issue to cause Qt to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2015-1858)\n\nRichard Moore and Fabian Vogt discovered that Qt incorrectly handled\ncertain malformed ICO images. If a user or automated system were tricked\ninto opening a specially crafted ICO image, a remote attacker could use\nthis issue to cause Qt to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2015-1859)\n\nRichard Moore and Fabian Vogt discovered that Qt incorrectly handled\ncertain malformed GIF images. If a user or automated system were tricked\ninto opening a specially crafted GIF image, a remote attacker could use\nthis issue to cause Qt to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2015-1860)\n","is_hidden":false,"release_packages":{"precise":[{"name":"qt4-x11","version":"4:4.8.1-0ubuntu4.9","description":"Qt 4 libraries","is_source":true},{"name":"libqtgui4","version":"4:4.8.1-0ubuntu4.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.1-0ubuntu4.9"}],"trusty":[{"name":"qt4-x11","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","description":"Qt 4 libraries","is_source":true},{"name":"qtbase-opensource-src","version":"5.2.1+dfsg-1ubuntu14.3","description":"Qt 5 libraries","is_source":true},{"name":"libqt4-assistant","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-core","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-dbus","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-declarative","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-declarative-folderlistmodel","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-declarative-gestures","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-declarative-particles","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-declarative-shaders","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-designer","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-dev","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-dev-bin","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-gui","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-help","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-network","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-opengl","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-opengl-dev","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-private-dev","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-qt3support","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-script","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-scripttools","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-sql","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-sql-mysql","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-sql-odbc","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-sql-psql","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-sql-sqlite","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-sql-tds","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-svg","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-test","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-webkit","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-xml","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt4-xmlpatterns","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqt5concurrent5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5core5a","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5dbus5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5gui5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5network5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5opengl5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5opengl5-dev","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5printsupport5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5sql5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5sql5-mysql","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5sql5-odbc","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5sql5-psql","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5sql5-sqlite","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5sql5-tds","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5test5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5widgets5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqt5xml5","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"libqtcore4","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqtdbus4","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"libqtgui4","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qdbus","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-default","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-demos","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-designer","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-dev-tools","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-doc","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-doc-html","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-linguist-tools","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-qmake","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-qmlviewer","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt4-qtconfig","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"},{"name":"qt5-default","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"qt5-qmake","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"qtbase5-dev","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"qtbase5-dev-tools","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"qtbase5-doc-html","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"qtbase5-examples","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"qtbase5-private-dev","version":"5.2.1+dfsg-1ubuntu14.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.2.1+dfsg-1ubuntu14.3","pocket":"security"},{"name":"qtcore4-l10n","version":"4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1","pocket":"security"}],"utopic":[{"name":"qt4-x11","version":"4:4.8.6+git49-gbc62005+dfsg-1ubuntu1.1","description":"Qt 4 libraries","is_source":true},{"name":"qtbase-opensource-src","version":"5.3.0+dfsg-2ubuntu9.1","description":"Qt 5 libraries","is_source":true},{"name":"libqt5gui5","version":"5.3.0+dfsg-2ubuntu9.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.3.0+dfsg-2ubuntu9.1"},{"name":"libqtgui4","version":"4:4.8.6+git49-gbc62005+dfsg-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.6+git49-gbc62005+dfsg-1ubuntu1.1"}],"vivid":[{"name":"qt4-x11","version":"4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu6.1","description":"Qt 4 libraries","is_source":true},{"name":"qtbase-opensource-src","version":"5.4.1+dfsg-2ubuntu4.1","description":"Qt 5 libraries","is_source":true},{"name":"libqt5gui5","version":"5.4.1+dfsg-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src","version_link":"https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.4.1+dfsg-2ubuntu4.1"},{"name":"libqtgui4","version":"4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu6.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qt4-x11","version_link":"https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu6.1"}]},"type":"USN","cves_ids":["CVE-2014-0190","CVE-2015-0295","CVE-2015-1858","CVE-2015-1859","CVE-2015-1860"]}]},{"id":"CVE-2014-0134","published":"2014-05-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3\nand Icehouse before 2014.1, when using libvirt to spawn images and\nuse_cow_images is set to false, allows remote authenticated users to read\ncertain compute host files by overwriting an instance disk with a crafted\nimage.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"1:2013.2.3-0ubuntu1 is now in saucy-updates\nintroduced in grizzly"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2247-1","https://www.cve.org/CVERecord?id=CVE-2014-0134"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742712","https://launchpad.net/bugs/1221190"],"patches":{"nova":["upstream: https://git.openstack.org/cgit/openstack/nova/commit/?id=dc8de426066969a3f0624fdc2a7b29371a2d55bf","upstream: https://git.openstack.org/cgit/openstack/nova/commit/?id=25e761acd56d4c820273fc0245ada06c500c1637"]},"tags":{"nova":["apparmor"]},"packages":[{"name":"nova","source":"https://ubuntu.com/security/cve?package=nova","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nova","debian":"https://tracker.debian.org/pkg/nova","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:2013.2.3-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2013.2.2-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":["USN-2247-1"],"notices":[{"id":"USN-2247-1","title":"OpenStack Nova vulnerabilities","summary":"Several security issues were fixed in OpenStack Nova.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-06-17T21:50:58.685639","description":"Darragh O'Reilly discovered that the Ubuntu packaging for OpenStack Nova\ndid not properly set up its sudo configuration. If a different flaw was\nfound in OpenStack Nova, this vulnerability could be used to escalate\nprivileges. This issue only affected Ubuntu 13.10 and Ubuntu 14.04 LTS.\n(CVE-2013-1068)\n\nBernhard M. Wiedemann and Pedraig Brady discovered that OpenStack Nova did\nnot properly verify the virtual size of a QCOW2 images. A remote\nauthenticated attacker could exploit this to create a denial of service via\ndisk consumption. This issue did not affect Ubuntu 14.04 LTS.\n(CVE-2013-4463, CVE-2013-4469)\n\nJuanFra Rodriguez Cardoso discovered that OpenStack Nova did not enforce\nSSL connections when Nova was configured to use QPid and qpid_protocol is\nset to 'ssl'. If a remote attacker were able to perform a machine-in-the-middle\nattack, this flaw could be exploited to view sensitive information. Ubuntu\ndoes not use QPid with Nova by default. This issue did not affect Ubuntu\n14.04 LTS. (CVE-2013-6491)\n\nLoganathan Parthipan discovered that OpenStack Nova did not properly create\nexpected files during KVM live block migration. A remote authenticated\nattacker could exploit this to obtain root disk snapshot contents via\nephemeral storage. This issue did not affect Ubuntu 14.04 LTS.\n(CVE-2013-7130)\n\nStanislaw Pitucha discovered that OpenStack Nova did not enforce the image\nformat when rescuing an instance. A remote authenticated attacker could\nexploit this to read host files. In the default installation, attackers\nwould be isolated by the libvirt guest AppArmor profile. This issue only\naffected Ubuntu 13.10. (CVE-2014-0134)\n\nMark Heckmann discovered that OpenStack Nova did not enforce RBAC policy\nwhen adding security group rules via the EC2 API. A remote authenticated\nuser could exploit this to gain unintended access to this API. This issue\nonly affected Ubuntu 13.10. (CVE-2014-0167)\n","is_hidden":false,"release_packages":{"precise":[{"name":"nova","version":"2012.1.3+stable-20130423-e52e6912-0ubuntu1.4","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"python-nova","version":"2012.1.3+stable-20130423-e52e6912-0ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/2012.1.3+stable-20130423-e52e6912-0ubuntu1.4"}],"saucy":[{"name":"nova","version":"1:2013.2.3-0ubuntu1.2","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"python-nova","version":"1:2013.2.3-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2013.2.3-0ubuntu1.2"}],"trusty":[{"name":"nova","version":"1:2014.1-0ubuntu1.2","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"nova-ajax-console-proxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-ec2","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-metadata","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-os-compute","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-api-os-volume","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-baremetal","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-cells","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-cert","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-common","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-kvm","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-libvirt","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-lxc","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-qemu","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-vmware","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-compute-xen","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-conductor","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-console","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-consoleauth","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-doc","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-network","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-novncproxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-objectstore","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-scheduler","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-spiceproxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-volume","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"nova-xvpvncproxy","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"},{"name":"python-nova","version":"1:2014.1-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/1:2014.1-0ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-1068","CVE-2013-4463","CVE-2013-4469","CVE-2013-6491","CVE-2013-7130","CVE-2014-0134","CVE-2014-0167"]}]},{"id":"CVE-2013-7041","published":"2014-05-08T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe pam_userdb module for Pam uses a case-insensitive method to compare\nhashed passwords, which makes it easier for attackers to guess the password\nvia a brute force attack.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"see additional comments in oss-security thread"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/12/09/5","https://ubuntu.com/security/notices/USN-2935-1","https://www.cve.org/CVERecord?id=CVE-2013-7041"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731368","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7041"],"patches":{"pam":["vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=731368"]},"tags":{},"packages":[{"name":"pam","source":"https://ubuntu.com/security/cve?package=pam","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pam","debian":"https://tracker.debian.org/pkg/pam","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.1.3-7ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.1.8-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.8-3.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.1.8-3.1ubuntu3","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.1.8-3.1ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2935-1"],"notices":[{"id":"USN-2935-1","title":"PAM vulnerabilities","summary":"Several security issues were fixed in PAM.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2016-03-16T13:45:39.506195","description":"It was discovered that the PAM pam_userdb module incorrectly used a\ncase-insensitive method when comparing hashed passwords. A local attacker\ncould possibly use this issue to make brute force attacks easier. This\nissue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2013-7041)\n\nSebastian Krahmer discovered that the PAM pam_timestamp module incorrectly\nperformed filtering. A local attacker could use this issue to create\narbitrary files, or possibly bypass authentication. This issue only\naffected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-2583)\n\nSebastien Macke discovered that the PAM pam_unix module incorrectly handled\nlarge passwords. A local attacker could possibly use this issue in certain\nenvironments to enumerate usernames or cause a denial of service.\n(CVE-2015-3238)\n","is_hidden":false,"release_packages":{"precise":[{"name":"pam","version":"1.1.3-7ubuntu2.1","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-modules","version":"1.1.3-7ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.3-7ubuntu2.1"}],"trusty":[{"name":"pam","version":"1.1.8-1ubuntu2.1","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-cracklib","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-doc","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-modules","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-modules-bin","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam-runtime","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam0g","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"},{"name":"libpam0g-dev","version":"1.1.8-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-1ubuntu2.1","pocket":"security"}],"wily":[{"name":"pam","version":"1.1.8-3.1ubuntu3.1","description":"Pluggable Authentication Modules","is_source":true},{"name":"libpam-modules","version":"1.1.8-3.1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pam","version_link":"https://launchpad.net/ubuntu/+source/pam/1.1.8-3.1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2013-7041","CVE-2014-2583","CVE-2015-3238"]}]},{"id":"CVE-2014-3124","published":"2014-05-07T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest\nHVM administrators to cause a denial of service (hypervisor crash) or\npossibly execute arbitrary code by leveraging a separate qemu-dm\nvulnerability to trigger invalid page table translations for unspecified\nmemory page types.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://xenbits.xenproject.org/xsa/advisory-92.html","https://www.cve.org/CVERecord?id=CVE-2014-3124"],"bugs":[""],"patches":{"xen-3.3":[],"xen":[]},"tags":{"xen-3.3":["universe-binary"],"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4.1.6.1-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"4.3.0-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.3","source":"https://ubuntu.com/security/cve?package=xen-3.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.3","debian":"https://tracker.debian.org/pkg/xen-3.3","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2913","published":"2014-05-07T10:55:00","updated_at":"2025-08-04T19:24:27.160437+00:00","description":"\nIncomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin\nExecutor (NRPE) 2.15 and earlier allows remote attackers to execute\narbitrary commands via a newline character in the -a option to\nlibexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It\nhas been reported that the vendor allows newlines as \"expected behavior.\"\nAlso, this issue can only occur when the administrator enables the\n\"dont_blame_nrpe\" option in nrpe.conf despite the \"HIGH security risk\"\nwarning within the comments","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"I marked this 'low' because arguments are discouraged for many\nenvironments, access to NRPE can be restricted with firewalling or\nother user access controls, and this might plausibly be a feature."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://seclists.org/fulldisclosure/2014/Apr/240","http://seclists.org/fulldisclosure/2014/Apr/242","https://www.cve.org/CVERecord?id=CVE-2014-2913"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=745272"],"patches":{"nagios-nrpe":[]},"tags":{},"packages":[{"name":"nagios-nrpe","source":"https://ubuntu.com/security/cve?package=nagios-nrpe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nagios-nrpe","debian":"https://tracker.debian.org/pkg/nagios-nrpe","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.15-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0130","published":"2014-05-07T10:55:00","updated_at":"2025-08-25T21:09:36.231518+00:00","description":"\nDirectory traversal vulnerability in\nactionpack/lib/abstract_controller/base.rb in the implicit-render\nimplementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and\n4.1.x before 4.1.1, when certain route globbing configurations are enabled,\nallows remote attackers to read arbitrary files via a crafted request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://groups.google.com/forum/message/raw?msg=rubyonrails-security/NkKc7vTW70o/NxW_PDBSG3AJ","https://www.cve.org/CVERecord?id=CVE-2014-0130","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"rails":[],"rails-4.0":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2:4.2.10-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2:4.2.10-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2:4.2.10-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.18, 4.0.5, 4.1.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:4.2.6-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"rails-4.0","source":"https://ubuntu.com/security/cve?package=rails-4.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails-4.0","debian":"https://tracker.debian.org/pkg/rails-4.0","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3230","published":"2014-05-07T00:00:00","updated_at":"2025-08-25T21:17:21.287852+00:00","description":"\nThe libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl,\nwhen using IO::Socket::SSL as the SSL socket class, allows attackers to\ndisable server certificate validation via the (1) HTTPS_CA_DIR or (2)\nHTTPS_CA_FILE environment variable.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, introduced by https://github.com/dagolden/lwp-protocol-https/commit/bcc46ce2dab53d2e2baa583f2243d6fc7d36dcc8\nfix for https://rt.cpan.org/Public/Bug/Display.html?id=81948\nintroduced the bug (6.04)"},{"author":"mdeslaur","note":"as of 2014-06-27, proposed patch is still being discussed"}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2292-1","https://www.cve.org/CVERecord?id=CVE-2014-3230"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746579"],"patches":{"liblwp-protocol-https-perl":["vendor: https://github.com/libwww-perl/lwp-protocol-https/pull/14"]},"tags":{},"packages":[{"name":"liblwp-protocol-https-perl","source":"https://ubuntu.com/security/cve?package=liblwp-protocol-https-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=liblwp-protocol-https-perl","debian":"https://tracker.debian.org/pkg/liblwp-protocol-https-perl","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"6.03-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6.04-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.04-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2292-1"],"notices":[{"id":"USN-2292-1","title":"LWP::Protocol::https vulnerability","summary":"LWP::Protocol::https could be made to expose sensitive information over the\nnetwork.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-07-17T17:45:15.152006","description":"It was discovered that the LWP::Protocol::https perl module incorrectly\ndisabled peer certificate verification completely when only hostname\nverification was requested to be disabled. If a remote attacker were able\nto perform a machine-in-the-middle attack, this flaw could possibly be\nexploited in certain scenarios to alter or compromise confidential\ninformation in applications that used the LWP::Protocol::https module.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"liblwp-protocol-https-perl","version":"6.04-2ubuntu0.1","description":"HTTPS driver for LWP::UserAgent","is_source":true},{"name":"liblwp-protocol-https-perl","version":"6.04-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/liblwp-protocol-https-perl","version_link":"https://launchpad.net/ubuntu/+source/liblwp-protocol-https-perl/6.04-2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-3230"]}]},{"id":"CVE-2014-0191","published":"2014-05-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe xmlParserHandlePEReference function in parser.c in libxml2 before\n2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion\nMiddleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads\nexternal parameter entities regardless of whether entity substitution or\nvalidation is enabled, which allows remote attackers to cause a denial of\nservice (resource consumption) via a crafted XML document.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/05/06/4","https://ubuntu.com/security/notices/USN-2214-1","https://www.cve.org/CVERecord?id=CVE-2014-0191"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1090976","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747309"],"patches":{"libxml2":["upstream: https://git.gnome.org/browse/libxml2/commit/?id=9cd1c3cfbd32655d60572c0a413e017260c854df"]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"lucid","status":"released","description":"2.7.6.dfsg-1ubuntu1.11","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.8.dfsg-5.1ubuntu4.7","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.8.0+dfsg1-5ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.9.1+dfsg1-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.9.1+dfsg1-3ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2214-1"],"notices":[{"id":"USN-2214-1","title":"libxml2 vulnerability","summary":"libxml2 could be made to consume resources if it processed a specially\ncrafted file.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-05-15T17:26:03.761934","description":"Daniel Berrange discovered that libxml2 would incorrectly perform entity\nsubstitution even when requested not to. If a user or automated system were\ntricked into opening a specially crafted document, an attacker could\npossibly cause resource consumption, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"libxml2","version":"2.7.6.dfsg-1ubuntu1.11","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.6.dfsg-1ubuntu1.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.6.dfsg-1ubuntu1.11"}],"precise":[{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.7","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.7"}],"quantal":[{"name":"libxml2","version":"2.8.0+dfsg1-5ubuntu2.5","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.8.0+dfsg1-5ubuntu2.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.8.0+dfsg1-5ubuntu2.5"}],"saucy":[{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu2.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu2.1"}],"trusty":[{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.1","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.1+dfsg1-3ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.1","pocket":"security"},{"name":"libxml2-dev","version":"2.9.1+dfsg1-3ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.1","pocket":"security"},{"name":"libxml2-doc","version":"2.9.1+dfsg1-3ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.1","pocket":"security"},{"name":"libxml2-udeb","version":"2.9.1+dfsg1-3ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.1","pocket":"security"},{"name":"libxml2-utils","version":"2.9.1+dfsg1-3ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.1","pocket":"security"},{"name":"python-libxml2","version":"2.9.1+dfsg1-3ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.1+dfsg1-3ubuntu4.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0191"]}]},{"id":"CVE-2013-7336","published":"2014-05-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt\nbefore 1.1.3 does not properly enter a monitor when performing seamless\nSPICE migration, which allows local users to cause a denial of service\n(NULL pointer dereference and libvirtd crash) by causing domblkstat to be\ncalled at the same time as the qemuMonitorGetSpiceMigrationStatus function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.redhat.com/archives/libvir-list/2013-September/msg01208.html","http://security.libvirt.org/2013/0021.html","https://ubuntu.com/security/notices/USN-2209-1","https://www.cve.org/CVERecord?id=CVE-2013-7336"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1009886"],"patches":{"libvirt":["upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=fea2550974137918c2bc9e01f3eb00421585450c"]},"tags":{},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.1.1-0ubuntu8.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.2.2-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2209-1"],"notices":[{"id":"USN-2209-1","title":"libvirt vulnerabilities","summary":"Several security issues were fixed in libvirt.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-05-07T17:52:17.290797","description":"It was discovered that libvirt incorrectly handled symlinks when using the\nLXC driver. An attacker could possibly use this issue to delete host\ndevices, create arbitrary nodes, and shutdown or power off the host.\n(CVE-2013-6456)\n\nMarian Krcmarik discovered that libvirt incorrectly handled seamless SPICE\nmigrations. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2013-7336)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"libvirt","version":"1.1.1-0ubuntu8.11","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt0","version":"1.1.1-0ubuntu8.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.1.1-0ubuntu8.11"},{"name":"libvirt-bin","version":"1.1.1-0ubuntu8.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.1.1-0ubuntu8.11"}]},"type":"USN","cves_ids":["CVE-2013-6456","CVE-2013-7336"]}]},{"id":"CVE-2014-3204","published":"2014-05-06T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnity before 7.2.1, as used in Ubuntu 14.04, does not properly handle\nkeyboard shortcuts, which allows physically proximate attackers to bypass\nthe lock screen and execute arbitrary commands, as demonstrated by\nright-clicking on the indicator bar and then pressing the ALT and F2 keys.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/05/03/1","http://www.openwall.com/lists/oss-security/2014/04/29/2","https://ubuntu.com/security/notices/USN-2184-1","https://www.cve.org/CVERecord?id=CVE-2014-3204"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1313885"],"patches":{"unity":[]},"tags":{},"packages":[{"name":"unity","source":"https://ubuntu.com/security/cve?package=unity","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unity","debian":"https://tracker.debian.org/pkg/unity","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.2.0+14.04.20140423-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3203","published":"2014-05-06T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict\naccess to the Dash when the lock screen is active, which allows physically\nproximate attackers to bypass the lock screen and execute arbitrary\ncommands, as demonstrated by pressing the SUPER key before the screen\nauto-locks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/05/03/1","http://www.openwall.com/lists/oss-security/2014/04/29/2","https://ubuntu.com/security/notices/USN-2184-1","https://www.cve.org/CVERecord?id=CVE-2014-3203"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308850"],"patches":{"unity":[]},"tags":{},"packages":[{"name":"unity","source":"https://ubuntu.com/security/cve?package=unity","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unity","debian":"https://tracker.debian.org/pkg/unity","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.2.0+14.04.20140423-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3202","published":"2014-05-06T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnity before 7.2.1 does not properly handle entry activation, which allows\nphysically proximate attackers to bypass the lock screen by holding the\nENTER key, which triggers the process to crash.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"fixed prior to release"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/05/03/1","http://www.openwall.com/lists/oss-security/2014/04/29/2","http://www.openwall.com/lists/oss-security/2014/04/26/2","http://www.openwall.com/lists/oss-security/2014/04/26/1","https://www.cve.org/CVERecord?id=CVE-2014-3202"],"bugs":["https://bugs.launchpad.net/unity/+bug/1308750","https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308572"],"patches":{"unity":[]},"tags":{},"packages":[{"name":"unity","source":"https://ubuntu.com/security/cve?package=unity","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unity","debian":"https://tracker.debian.org/pkg/unity","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.2.0+14.04.20140416-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0193","published":"2014-05-06T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1,\n3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows\nremote attackers to cause a denial of service (memory consumption) via a\nTextWebSocketFrame followed by a long stream of\nContinuationWebSocketFrames.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://netty.io/news/2014/04/30/release-day.html","https://www.cve.org/CVERecord?id=CVE-2014-0193"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746639"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:4.1.7-4","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.9, 3.7.1, 3.8.2, 3.9.1, 4.0.19","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":65540,"limit":20,"total_results":79316}