{"cves":[{"id":"CVE-2014-2288","published":"2014-04-18T22:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe PJSIP channel driver in Asterisk Open Source 12.x before 12.1.1, when\nqualify_frequency \"is enabled on an AOR and the remote SIP server\nchallenges for authentication of the resulting OPTIONS request,\" allows\nremote attackers to cause a denial of service (crash) via a PJSIP endpoint\nthat does not have an associated outgoing request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://issues.asterisk.org/jira/browse/ASTERISK-23210","http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130426.html","http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130400.html","http://downloads.asterisk.org/pub/security/AST-2014-003.html","http://downloads.asterisk.org/pub/security/AST-2014-003-12.diff","https://www.cve.org/CVERecord?id=CVE-2014-2288"],"bugs":[""],"patches":{"asterisk":[]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"12.1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2287","published":"2014-04-18T22:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nchannels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x\nbefore 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15\nbefore 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain\nconfiguration, allows remote authenticated users to cause a denial of\nservice (channel and file descriptor consumption) via an INVITE request\nwith a (1) Session-Expires or (2) Min-SE header with a malformed or invalid\nvalue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://issues.asterisk.org/jira/browse/ASTERISK-23373","http://www.mandriva.com/security/advisories?name=MDVSA-2014:078","http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130426.html","http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130400.html","http://downloads.asterisk.org/pub/security/AST-2014-002.html","http://downloads.asterisk.org/pub/security/AST-2014-002-1.8.diff","https://www.cve.org/CVERecord?id=CVE-2014-2287"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741313"],"patches":{"asterisk":["upstream: http://downloads.asterisk.org/pub/security/AST-2014-002-1.8.diff","upstream: http://downloads.asterisk.org/pub/security/AST-2014-002-11.diff"]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:11.8.1~dfsg-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2286","published":"2014-04-18T22:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmain/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before\n11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before\n1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a\ndenial of service (stack consumption) and possibly execute arbitrary code\nvia an HTTP request with a large number of Cookie headers.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://issues.asterisk.org/jira/browse/ASTERISK-23340","http://www.mandriva.com/security/advisories?name=MDVSA-2014:078","http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130426.html","http://lists.fedoraproject.org/pipermail/package-announce/2014-March/130400.html","http://downloads.asterisk.org/pub/security/AST-2014-001.html","http://downloads.asterisk.org/pub/security/AST-2014-001-1.8.diff","https://www.cve.org/CVERecord?id=CVE-2014-2286"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741313"],"patches":{"asterisk":["upstream: http://downloads.asterisk.org/pub/security/AST-2014-001-1.8.diff","upstream: http://downloads.asterisk.org/pub/security/AST-2014-001-11.diff"]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:11.8.1~dfsg-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:11.8.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2014","published":"2014-04-18T22:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nimapsync before 1.584, when running with the --tls option, attempts a\ncleartext login when a certificate verification failure occurs, which\nallows remote attackers to obtain credentials by sniffing the network.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/02/18","https://www.cve.org/CVERecord?id=CVE-2014-2014"],"bugs":[""],"patches":{"imapsync":[]},"tags":{},"packages":[{"name":"imapsync","source":"https://ubuntu.com/security/cve?package=imapsync","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imapsync","debian":"https://tracker.debian.org/pkg/imapsync","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4279","published":"2014-04-18T22:14:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nimapsync 1.564 and earlier performs a release check by default, which sends\nsensitive information (imapsync, operating system, and Perl version) to the\ndeveloper's site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/01/16","http://imapsync.lamiral.info","https://www.cve.org/CVERecord?id=CVE-2013-4279"],"bugs":[""],"patches":{"imapsync":[]},"tags":{},"packages":[{"name":"imapsync","source":"https://ubuntu.com/security/cve?package=imapsync","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imapsync","debian":"https://tracker.debian.org/pkg/imapsync","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4290","published":"2014-04-18T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in OpenJPEG before 1.5.2 allows remote\nattackers to have unspecified impact via unknown vectors to (1)\nlib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c, or (3)\nlib/openjp3d/event.c.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"According to Debian:\nJP3D code not built in the binary package."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-4290"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=722540"],"patches":{"openjpeg":[]},"tags":{},"packages":[{"name":"openjpeg","source":"https://ubuntu.com/security/cve?package=openjpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjpeg","debian":"https://tracker.debian.org/pkg/openjpeg","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4289","published":"2014-04-18T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2\nallow remote attackers to have unspecified impact and vectors, which\ntrigger a heap-based buffer overflow.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"According to Debian:\nJP3D code not built in the binary package."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-4289"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=722540"],"patches":{"openjpeg":[]},"tags":{},"packages":[{"name":"openjpeg","source":"https://ubuntu.com/security/cve?package=openjpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjpeg","debian":"https://tracker.debian.org/pkg/openjpeg","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2856","published":"2014-04-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in scheduler/client.c in Common\nUnix Printing System (CUPS) before 1.7.2 allows remote attackers to inject\narbitrary web script or HTML via the URL path, related to the\nis_path_absolute function.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"successfully reproduced on lucid+\npatch in bug is what's in 1.7.2"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/04/15","https://ubuntu.com/security/notices/USN-2172-1","https://www.cve.org/CVERecord?id=CVE-2014-2856"],"bugs":["http://www.cups.org/str.php?L4356"],"patches":{"cups":["upstream: http://www.cups.org/strfiles.php/3268/str4356.patch"]},"tags":{},"packages":[{"name":"cups","source":"https://ubuntu.com/security/cve?package=cups","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups","debian":"https://tracker.debian.org/pkg/cups","statuses":[{"release_codename":"lucid","status":"released","description":"1.4.3-1ubuntu1.11","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.5.3-0ubuntu8.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.6.1-0ubuntu11.6","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.7.0~rc1-0ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.7.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2172-1"],"notices":[{"id":"USN-2172-1","title":"CUPS vulnerability","summary":"CUPS could be made to expose sensitive information over the network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-24T15:25:44.324791","description":"Alex Korobkin discovered that the CUPS web interface incorrectly protected\nagainst cross-site scripting (XSS) attacks. If an authenticated user were\ntricked into visiting a malicious website while logged into CUPS, a remote\nattacker could modify the CUPS configuration and possibly steal\nconfidential data.\n","is_hidden":false,"release_packages":{"precise":[{"name":"cups","version":"1.5.3-0ubuntu8.2","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.5.3-0ubuntu8.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.5.3-0ubuntu8.2"}],"saucy":[{"name":"cups","version":"1.7.0~rc1-0ubuntu5.3","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.7.0~rc1-0ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.7.0~rc1-0ubuntu5.3"}],"lucid":[{"name":"cups","version":"1.4.3-1ubuntu1.11","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.4.3-1ubuntu1.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.4.3-1ubuntu1.11"}],"quantal":[{"name":"cups","version":"1.6.1-0ubuntu11.6","description":"Common UNIX Printing System(tm)","is_source":true},{"name":"cups","version":"1.6.1-0ubuntu11.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cups","version_link":"https://launchpad.net/ubuntu/+source/cups/1.6.1-0ubuntu11.6"}]},"type":"USN","cves_ids":["CVE-2014-2856"]}]},{"id":"CVE-2014-0182","published":"2014-04-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in the virtio_load function in\nhw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to\nexecute arbitrary code via a crafted config length in a savevm image.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2342-1","https://www.cve.org/CVERecord?id=CVE-2014-0182"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0182"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=a890a2f9137ac3cf5b607649e66a6f3a5512d8dc","upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=2f5732e9648fcddc8759a8fd25c0b41a38352be6"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"lucid","status":"released","description":"0.12.3+noroms-0ubuntu9.24","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.17","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2342-1"],"notices":[{"id":"USN-2342-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2014-09-08T17:35:27.624875","description":"Michael S. Tsirkin, Anthony Liguori, and Michael Roth discovered multiple\nissues with QEMU state loading after migration. An attacker able to modify\nthe state data could use these issues to cause a denial of service, or\npossibly execute arbitrary code. (CVE-2013-4148, CVE-2013-4149,\nCVE-2013-4150, CVE-2013-4151, CVE-2013-4526, CVE-2013-4527, CVE-2013-4529,\nCVE-2013-4530, CVE-2013-4531, CVE-2013-4532, CVE-2013-4533, CVE-2013-4534,\nCVE-2013-4535, CVE-2013-4536, CVE-2013-4537, CVE-2013-4538, CVE-2013-4539,\nCVE-2013-4540, CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182,\nCVE-2014-3461)\n\nKevin Wolf, Stefan Hajnoczi, Fam Zheng, Jeff Cody, Stefan Hajnoczi, and\nothers discovered multiple issues in the QEMU block drivers. An attacker\nable to modify disk images could use these issues to cause a denial of\nservice, or possibly execute arbitrary code. (CVE-2014-0142, CVE-2014-0143,\nCVE-2014-0144, CVE-2014-0145, CVE-2014-0146, CVE-2014-0147, CVE-2014-0222,\nCVE-2014-0223)\n\nIt was discovered that QEMU incorrectly handled certain PCIe bus hotplug\noperations. A malicious guest could use this issue to crash the QEMU host,\nresulting in a denial of service. (CVE-2014-3471)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.24","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/0.12.3+noroms-0ubuntu9.24"}],"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.17","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.17"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.3","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-4148","CVE-2013-4149","CVE-2013-4150","CVE-2013-4151","CVE-2013-4526","CVE-2013-4527","CVE-2013-4529","CVE-2013-4530","CVE-2013-4531","CVE-2013-4532","CVE-2013-4533","CVE-2013-4534","CVE-2013-4535","CVE-2013-4536","CVE-2013-4537","CVE-2013-4538","CVE-2013-4539","CVE-2013-4540","CVE-2013-4541","CVE-2013-4542","CVE-2013-6399","CVE-2014-0142","CVE-2014-0143","CVE-2014-0144","CVE-2014-0145","CVE-2014-0146","CVE-2014-0147","CVE-2014-0182","CVE-2014-0222","CVE-2014-0223","CVE-2014-3461","CVE-2014-3471"]}]},{"id":"CVE-2014-0150","published":"2014-04-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in the virtio_net_handle_mac function in\nhw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to\nexecute arbitrary code via a MAC addresses table update request, which\ntriggers a heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://article.gmane.org/gmane.comp.emulators.qemu/266713","https://ubuntu.com/security/notices/USN-2182-1","https://www.cve.org/CVERecord?id=CVE-2014-0150"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744221","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0150"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=edc243851279e3393000b28b6b69454cae1190ef"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.5.0+dfsg-3ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0~rc1+dfsg-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"lucid","status":"released","description":"0.12.3+noroms-0ubuntu9.22","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.0+noroms-0ubuntu14.14","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.2.0+noroms-0ubuntu2.12.10.7","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2182-1"],"notices":[{"id":"USN-2182-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2014-04-28T12:51:10.329125","description":"Michael S. Tsirkin discovered that QEMU incorrectly handled vmxnet3\ndevices. A local guest could possibly use this issue to cause a denial of\nservice, or possibly execute arbitrary code on the host. This issue only\napplied to Ubuntu 13.10 and Ubuntu 14.04 LTS. (CVE-2013-4544)\n\nMichael S. Tsirkin discovered that QEMU incorrectly handled virtio-net\nMAC addresses. A local guest could possibly use this issue to cause a\ndenial of service, or possibly execute arbitrary code on the host.\n(CVE-2014-0150)\n\nBenoĆ®t Canet discovered that QEMU incorrectly handled SMART self-tests. A\nlocal guest could possibly use this issue to cause a denial of service, or\npossibly execute arbitrary code on the host. (CVE-2014-2894)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.22","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"0.12.3+noroms-0ubuntu9.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/0.12.3+noroms-0ubuntu9.22"}],"precise":[{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.14","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.0+noroms-0ubuntu14.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.0+noroms-0ubuntu14.14"}],"quantal":[{"name":"qemu-kvm","version":"1.2.0+noroms-0ubuntu2.12.10.7","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-kvm","version":"1.2.0+noroms-0ubuntu2.12.10.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu-kvm","version_link":"https://launchpad.net/ubuntu/+source/qemu-kvm/1.2.0+noroms-0ubuntu2.12.10.7"}],"saucy":[{"name":"qemu","version":"1.5.0+dfsg-3ubuntu5.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1.5.0+dfsg-3ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.4"},{"name":"qemu-system-arm","version":"1.5.0+dfsg-3ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.4"},{"name":"qemu-system-mips","version":"1.5.0+dfsg-3ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.4"},{"name":"qemu-system-misc","version":"1.5.0+dfsg-3ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.4"},{"name":"qemu-system-ppc","version":"1.5.0+dfsg-3ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.4"},{"name":"qemu-system-sparc","version":"1.5.0+dfsg-3ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.4"},{"name":"qemu-system-x86","version":"1.5.0+dfsg-3ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1.5.0+dfsg-3ubuntu5.4"}],"trusty":[{"name":"qemu","version":"2.0.0~rc1+dfsg-0ubuntu3.1","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-common","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-user","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"},{"name":"qemu-utils","version":"2.0.0~rc1+dfsg-0ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0~rc1+dfsg-0ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2013-4544","CVE-2014-0150","CVE-2014-2894"]}]},{"id":"CVE-2014-2707","published":"2014-04-17T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP\nprinters to execute arbitrary commands via shell metacharacters in the (1)\nmodel or (2) PDL, related to \"System V interface scripts generated for\nqueues.\"","ubuntu_description":"","notes":[{"author":"jdstrand","note":"1.0.51 was an incomplete fix."},{"author":"mdeslaur","note":"CVE number pending for incomplete fix."}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/04/01/4","http://www.openwall.com/lists/oss-security/2014/04/25/7","https://ubuntu.com/security/notices/USN-2210-1","https://www.cve.org/CVERecord?id=CVE-2014-2707"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/cups-filters/+bug/1316229","https://bugzilla.novell.com/show_bug.cgi?id=871327"],"patches":{"cups-filters":["upstream: http://bzr.linuxfoundation.org/loggerhead/openprinting/cups-filters/revision/7194"]},"tags":{},"packages":[{"name":"cups-filters","source":"https://ubuntu.com/security/cve?package=cups-filters","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cups-filters","debian":"https://tracker.debian.org/pkg/cups-filters","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.0.40-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.52-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.53","component":null,"pocket":"security"}]}],"notices_ids":["USN-2210-1"],"notices":[{"id":"USN-2210-1","title":"cups-filters vulnerability","summary":"Several security issues were fixed in cups-filters.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-05-08T15:32:29.775041","description":"Sebastian Krahmer discovered that cups-browsed incorrectly filtered remote\nprinter names and strings. A remote attacker could use this issue to\npossibly execute arbitrary commands. (CVE-2014-2707)\n\nJohannes Meixner discovered that cups-browsed ignored invalid BrowseAllow\ndirectives. This could cause it to accept browse packets from all hosts,\ncontrary to intended configuration.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"cups-filters","version":"1.0.52-0ubuntu1.1","description":"OpenPrinting CUPS Filters","is_source":true},{"name":"cups-browsed","version":"1.0.52-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.1","pocket":"security"},{"name":"cups-filters","version":"1.0.52-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.1","pocket":"security"},{"name":"cups-filters-core-drivers","version":"1.0.52-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.1","pocket":"security"},{"name":"libcupsfilters-dev","version":"1.0.52-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.1","pocket":"security"},{"name":"libcupsfilters1","version":"1.0.52-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.1","pocket":"security"},{"name":"libfontembed-dev","version":"1.0.52-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.1","pocket":"security"},{"name":"libfontembed1","version":"1.0.52-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cups-filters","version_link":"https://launchpad.net/ubuntu/+source/cups-filters/1.0.52-0ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-2707"]}]},{"id":"CVE-2014-0085","published":"2014-04-17T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nJBoss Fuse did not enable encrypted passwords by default in its usage of\nApache Zookeeper. This permitted sensitive information disclosure via\nlogging to local users. Note: this description has been updated; previous\ntext mistakenly identified the source of the flaw as Zookeeper. Previous\ntext: Apache Zookeeper logs cleartext admin passwords, which allows local\nusers to obtain sensitive information by reading the log.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"Not for us, JBoss Fuse"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-0085"],"bugs":[""],"patches":{"zookeeper":[]},"tags":{},"packages":[{"name":"zookeeper","source":"https://ubuntu.com/security/cve?package=zookeeper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zookeeper","debian":"https://tracker.debian.org/pkg/zookeeper","statuses":[{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0071","published":"2014-04-17T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPackStack in Red Hat OpenStack 4.0 does not enforce the default security\ngroups when deployed to Neutron, which allows remote attackers to bypass\nintended access restrictions and make unauthorized connections.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"CVE is actually assigned to packstack, not sure if the neutron\npatch is actually a vulnerability fix."},{"author":"jdstrand","note":"per upstream, only Icehouse is affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2014-0071"],"bugs":["https://bugs.launchpad.net/devstack/+bug/1252620","https://bugs.launchpad.net/nova/+bug/1112912","https://bugzilla.redhat.com/show_bug.cgi?id=1064163"],"patches":{"neutron":["upstream: https://review.openstack.org/#/c/72452/","upstream: https://git.openstack.org/cgit/openstack/neutron/commit/?id=be8a06894390af032e8e0aea2108da4780678cc7"]},"tags":{},"packages":[{"name":"neutron","source":"https://ubuntu.com/security/cve?package=neutron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neutron","debian":"https://tracker.debian.org/pkg/neutron","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1:2013.2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1:2014.1~b3-0ubuntu1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0054","published":"2014-04-17T14:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework\nbefore 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity\nresolution, which allows remote attackers to read arbitrary files, cause a\ndenial of service, and conduct CSRF attacks via crafted XML, aka an XML\nExternal Entity (XXE) issue. NOTE: this vulnerability exists because of an\nincomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.gopivotal.com/security/cve-2014-0054","https://www.cve.org/CVERecord?id=CVE-2014-0054"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741604"],"patches":{"libspring-java":["upstream: https://github.com/spring-projects/spring-framework/commit/edba32b3093703d5e9ed42b5b8ec23ecc1998398#diff-1f3f1d5cdab9ac92d1ca5ec7def8f131"]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.0.6.RELEASE-13","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2855","published":"2014-04-17T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe check_secret function in authenticate.c in rsync 3.1.0 and earlier\nallows remote attackers to cause a denial of service (infinite loop and CPU\nconsumption) via a user name which does not exist in the secrets file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only in 3.1.0"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2171-1","https://www.cve.org/CVERecord?id=CVE-2014-2855"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=10551","https://bugs.launchpad.net/ubuntu/+source/rsync/+bug/1307230"],"patches":{"rsync":["upstream: https://git.samba.org/?p=rsync.git;a=commit;h=0dedfbce2c1b851684ba658861fe9d620636c56a"]},"tags":{},"packages":[{"name":"rsync","source":"https://ubuntu.com/security/cve?package=rsync","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rsync","debian":"https://tracker.debian.org/pkg/rsync","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.1.0-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2171-1"],"notices":[{"id":"USN-2171-1","title":"rsync vulnerability","summary":"rsync could be made to consume resources if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T14:41:32.824133","description":"Ryan Finnie discovered that the rsync daemon incorrectly handled invalid\nusernames. A remote attacker could use this issue to cause rsync to consume\nresources, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"rsync","version":"3.1.0-2ubuntu0.1","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.1.0-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":"https://launchpad.net/ubuntu/+source/rsync/3.1.0-2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-2855"]}]},{"id":"CVE-2014-2338","published":"2014-04-16T18:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nIKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass\nauthentication by rekeying an IKE_SA during (1) initiation or (2)\nre-authentication, which triggers the IKE_SA state to be set to\nestablished.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.strongswan.org/blog/2014/04/14/strongswan-authentication-bypass-vulnerability-%28cve-2014-2338%29.html","http://www.debian.org/security/2014/dsa-2903","https://www.cve.org/CVERecord?id=CVE-2014-2338"],"bugs":[""],"patches":{"strongswan":[]},"tags":{},"packages":[{"name":"strongswan","source":"https://ubuntu.com/security/cve?package=strongswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=strongswan","debian":"https://tracker.debian.org/pkg/strongswan","statuses":[{"release_codename":"vivid","status":"released","description":"5.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"5.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"5.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"5.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.1.2-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.2-4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"5.1.2-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1764","published":"2014-04-16T18:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users\nto downgrade packages via the \"install updates\" method.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, Zypp backend specific to SuSE"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/02/25","https://www.cve.org/CVERecord?id=CVE-2013-1764"],"bugs":[""],"patches":{"packagekit":[]},"tags":{},"packages":[{"name":"packagekit","source":"https://ubuntu.com/security/cve?package=packagekit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=packagekit","debian":"https://tracker.debian.org/pkg/packagekit","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-0460","published":"2014-04-16T18:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe init script in kbd, possibly 1.14.1 and earlier, allows local users to\noverwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"may have been specific to the suse init script"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.suse.com/support/security/advisories/2011_7_sr.html","https://www.cve.org/CVERecord?id=CVE-2011-0460"],"bugs":[""],"patches":{"kbd":[]},"tags":{},"packages":[{"name":"kbd","source":"https://ubuntu.com/security/cve?package=kbd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kbd","debian":"https://tracker.debian.org/pkg/kbd","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"no initscript","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"no initscript","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"no initscript","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"no initscript","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"no initscript","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"no initscript","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2451","published":"2014-04-16T02:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows\nremote authenticated users to affect availability via unknown vectors\nrelated to Privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://www.cve.org/CVERecord?id=CVE-2014-2451"],"bugs":[""],"patches":{"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.6.16-1~exp1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2450","published":"2014-04-16T02:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows\nremote authenticated users to affect availability via unknown vectors\nrelated to Optimizer.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://www.cve.org/CVERecord?id=CVE-2014-2450"],"bugs":[""],"patches":{"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.16","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.6.16-1~exp1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":65660,"limit":20,"total_results":79316}