{"cves":[{"id":"CVE-2013-5705","published":"2014-04-15T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\napache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers\nto bypass rules by using chunked transfer coding with a capitalized Chunked\nvalue in the Transfer-Encoding HTTP header.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://martin.swende.se/blog/HTTPChunked.html","https://www.cve.org/CVERecord?id=CVE-2013-5705"],"bugs":[""],"patches":{"modsecurity-apache":["upstream: https://github.com/SpiderLabs/ModSecurity/commit/f8d441cd25172fdfe5b613442fedfc0da3cc333d"],"libapache-mod-security":["upstream: https://github.com/SpiderLabs/ModSecurity/commit/f8d441cd25172fdfe5b613442fedfc0da3cc333d"]},"tags":{},"packages":[{"name":"libapache-mod-security","source":"https://ubuntu.com/security/cve?package=libapache-mod-security","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache-mod-security","debian":"https://tracker.debian.org/pkg/libapache-mod-security","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"modsecurity-apache","source":"https://ubuntu.com/security/cve?package=modsecurity-apache","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=modsecurity-apache","debian":"https://tracker.debian.org/pkg/modsecurity-apache","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.7-1, 2.7.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2580","published":"2014-04-15T00:00:00","updated_at":"2026-07-04T07:35:33.912045+00:00","description":"\nThe netback driver in Xen, when using certain Linux versions that do not\nallow sleeping in softirq context, allows local guest administrators to\ncause a denial of service (\"scheduling while atomic\" error and host crash)\nvia a malformed packet, which causes a mutex to be taken when trying to\ndisable the interface.","ubuntu_description":"\nTörök Edwin discovered a flaw with Xen netback driver when used with Linux\nconfigurations that do not allow sleeping in softirq context. A guest\nadministrator could exploit this flaw to cause a denial of service (system\ncrash) on the host.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/03/25","http://xenbits.xenproject.org/xsa/advisory-90.html","https://ubuntu.com/security/notices/USN-2226-1","https://ubuntu.com/security/notices/USN-2260-1","https://www.cve.org/CVERecord?id=CVE-2014-2580"],"bugs":["https://launchpad.net/bugs/1340085"],"patches":{"linux":["break-fix: b3f980bd827e6e81a050c518d60ed7811a83061d e9d8b2c2968499c1f96563e6522c56958d5a1d0d"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-raspi2":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"]},"packages":[{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-27.50","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.15.0-1.5","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.13.0-27.50~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2226-1","USN-2260-1"],"notices":[{"id":"USN-2226-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-05-27T06:49:10.556919","description":"\nMatthew Daley reported an information leak in the floppy disk driver of the\nLinux kernel. An unprivileged local user could exploit this flaw to obtain\npotentially sensitive information from kernel memory. (CVE-2014-1738)\n\nMatthew Daley reported a flaw in the handling of ioctl commands by the\nfloppy disk driver in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges if the floppy disk\nmodule is loaded. (CVE-2014-1737)\n\nA flaw was discovered in the handling of network packets when mergeable\nbuffers are disabled for virtual machines in the Linux kernel. Guest OS\nusers may exploit this flaw to cause a denial of service (host OS crash) or\npossibly gain privilege on the host OS. (CVE-2014-0077)\n\nTörök Edwin discovered a flaw with Xen netback driver when used with\nLinux configurations that do not allow sleeping in softirq context. A guest\nadministrator could exploit this flaw to cause a denial of service (system\ncrash) on the host. (CVE-2014-2580)\n\nA flaw was discovered in the Linux kernel's ping sockets. An unprivileged\nlocal user could exploit this flaw to cause a denial of service (system\ncrash) or possibly gain privileges via a crafted application.\n(CVE-2014-2851)\n\nHannes Frederic Sowa reported a hash collision ordering problem in the xfs\nfilesystem in the Linux kernel. A local user could exploit this flaw to\ncause filesystem corruption and a denial of service (oops or panic).\n(CVE-2014-7283)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-27.50","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-27-generic","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-generic-lpae","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-lowlatency","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc-e500","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc-e500mc","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc-smp","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc64-emb","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-3.13.0-27-powerpc64-smp","version":"3.13.0-27.50","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"},{"name":"linux-image-extra-3.13.0-27-generic","version":"3.13.0-27.50","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-27.50","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0077","CVE-2014-1737","CVE-2014-1738","CVE-2014-2580","CVE-2014-2851","CVE-2014-7283"]},{"id":"USN-2260-1","title":"Linux kernel (Trusty HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-06-27T08:47:01.477060","description":"\nA flaw was discovered in the Linux kernel's pseudo tty (pty) device. An\nunprivileged user could exploit this flaw to cause a denial of service\n(system crash) or potentially gain administrator privileges.\n(CVE-2014-0196)\n\nPinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An\nunprivileged local user could exploit this flaw to cause a denial of\nservice (system crash) or gain administrative privileges. (CVE-2014-3153)\n\nMatthew Daley reported an information leak in the floppy disk driver of the\nLinux kernel. An unprivileged local user could exploit this flaw to obtain\npotentially sensitive information from kernel memory. (CVE-2014-1738)\n\nMatthew Daley reported a flaw in the handling of ioctl commands by the\nfloppy disk driver in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges if the floppy disk\nmodule is loaded. (CVE-2014-1737)\n\nA flaw was discovered in the handling of network packets when mergeable\nbuffers are disabled for virtual machines in the Linux kernel. Guest OS\nusers may exploit this flaw to cause a denial of service (host OS crash) or\npossibly gain privilege on the host OS. (CVE-2014-0077)\n\nAn information leak was discovered in the netfilter subsystem of the Linux\nkernel. An attacker could exploit this flaw to obtain sensitive information\nfrom kernel memory. (CVE-2014-2568)\n\nTörök Edwin discovered a flaw with Xen netback driver when used with\nLinux configurations that do not allow sleeping in softirq context. A guest\nadministrator could exploit this flaw to cause a denial of service (system\ncrash) on the host. (CVE-2014-2580)\n\nA flaw was discovered in the Linux kernel's ping sockets. An unprivileged\nlocal user could exploit this flaw to cause a denial of service (system\ncrash) or possibly gain privileges via a crafted application.\n(CVE-2014-2851)\n\nSasha Levin reported a bug in the Linux kernel's virtual memory management\nsubsystem. An unprivileged local user could exploit this flaw to cause a\ndenial of service (system crash). (CVE-2014-3122)\n\nHannes Frederic Sowa reported a hash collision ordering problem in the xfs\nfilesystem in the Linux kernel. A local user could exploit this flaw to\ncause filesystem corruption and a denial of service (oops or panic).\n(CVE-2014-7283)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-30.54~precise2","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-3.13.0-30-generic","version":"3.13.0-30.54~precise2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-30.54~precise2"},{"name":"linux-image-3.13.0-30-generic-lpae","version":"3.13.0-30.54~precise2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-30.54~precise2"}]},"type":"USN","cves_ids":["CVE-2014-0077","CVE-2014-0196","CVE-2014-1737","CVE-2014-1738","CVE-2014-2568","CVE-2014-2580","CVE-2014-2851","CVE-2014-3122","CVE-2014-3153","CVE-2014-7283"]}]},{"id":"CVE-2014-2440","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Client component in Oracle MySQL\n5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect\nconfidentiality, integrity, and availability via unknown vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no indication that 5.1 is vulnerable, and no details, so\nmarking as not-affected for now."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2170-1","https://www.cve.org/CVERecord?id=CVE-2014-2440"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2440","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744910","https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1309662"],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.37-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.37-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.37-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.37-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.37","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.17-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.17","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2170-1"],"notices":[{"id":"USN-2170-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T12:56:46.008447","description":"Multiple security issues were discovered in MySQL and this update includes\na new upstream MySQL version to fix these issues. MySQL has been updated to\n5.5.37.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html\nhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html\n\nAdditionally, Matthias Reichl discovered that the mysql-5.5 packages were\nmissing the patches applied previously in the mysql-5.1 packages to drop\nthe default test database and localhost permissions granting access to any\ndatabases starting with \"test_\". This update reintroduces these patches for\nUbuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases\nand permissions will not be modified on upgrade. To manually restrict\naccess for existing installations, please refer to the following:\n\nhttp://dev.mysql.com/doc/refman/5.5/en/default-privileges.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.10.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.13.10.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0001","CVE-2014-0384","CVE-2014-2419","CVE-2014-2430","CVE-2014-2431","CVE-2014-2432","CVE-2014-2436","CVE-2014-2438","CVE-2014-2440"]}]},{"id":"CVE-2014-2438","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and\n5.6.15 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to Replication.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no indication that 5.1 is vulnerable, and no details, so\nmarking as not-affected for now."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2170-1","https://www.cve.org/CVERecord?id=CVE-2014-2438"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2438","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744910","https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1309662"],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.37-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.37-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.37-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.37-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.36","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.6.16-1~exp1]]","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2170-1"],"notices":[{"id":"USN-2170-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T12:56:46.008447","description":"Multiple security issues were discovered in MySQL and this update includes\na new upstream MySQL version to fix these issues. MySQL has been updated to\n5.5.37.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html\nhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html\n\nAdditionally, Matthias Reichl discovered that the mysql-5.5 packages were\nmissing the patches applied previously in the mysql-5.1 packages to drop\nthe default test database and localhost permissions granting access to any\ndatabases starting with \"test_\". This update reintroduces these patches for\nUbuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases\nand permissions will not be modified on upgrade. To manually restrict\naccess for existing installations, please refer to the following:\n\nhttp://dev.mysql.com/doc/refman/5.5/en/default-privileges.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.10.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.13.10.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0001","CVE-2014-0384","CVE-2014-2419","CVE-2014-2430","CVE-2014-2431","CVE-2014-2432","CVE-2014-2436","CVE-2014-2438","CVE-2014-2440"]}]},{"id":"CVE-2014-2436","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and\n5.6.16 and earlier allows remote authenticated users to affect\nconfidentiality, integrity, and availability via vectors related to RBR.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no indication that 5.1 is vulnerable, and no details, so\nmarking as not-affected for now."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2170-1","https://www.cve.org/CVERecord?id=CVE-2014-2436"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2436","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744910","https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1309662"],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.37-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.37-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.37-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.37-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.37","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.17-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.17","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2170-1"],"notices":[{"id":"USN-2170-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T12:56:46.008447","description":"Multiple security issues were discovered in MySQL and this update includes\na new upstream MySQL version to fix these issues. MySQL has been updated to\n5.5.37.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html\nhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html\n\nAdditionally, Matthias Reichl discovered that the mysql-5.5 packages were\nmissing the patches applied previously in the mysql-5.1 packages to drop\nthe default test database and localhost permissions granting access to any\ndatabases starting with \"test_\". This update reintroduces these patches for\nUbuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases\nand permissions will not be modified on upgrade. To manually restrict\naccess for existing installations, please refer to the following:\n\nhttp://dev.mysql.com/doc/refman/5.5/en/default-privileges.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.10.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.13.10.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0001","CVE-2014-0384","CVE-2014-2419","CVE-2014-2430","CVE-2014-2431","CVE-2014-2432","CVE-2014-2436","CVE-2014-2438","CVE-2014-2440"]}]},{"id":"CVE-2014-2432","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability Oracle the MySQL Server component 5.5.35 and\nearlier and 5.6.15 and earlier allows remote authenticated users to affect\navailability via unknown vectors related to Federated.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no indication that 5.1 is vulnerable, and no details, so\nmarking as not-affected for now."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2170-1","https://www.cve.org/CVERecord?id=CVE-2014-2432"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2432","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744910","https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1309662"],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.37-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.37-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.37-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.37-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.36","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.6.16-1~exp1]]","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2170-1"],"notices":[{"id":"USN-2170-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T12:56:46.008447","description":"Multiple security issues were discovered in MySQL and this update includes\na new upstream MySQL version to fix these issues. MySQL has been updated to\n5.5.37.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html\nhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html\n\nAdditionally, Matthias Reichl discovered that the mysql-5.5 packages were\nmissing the patches applied previously in the mysql-5.1 packages to drop\nthe default test database and localhost permissions granting access to any\ndatabases starting with \"test_\". This update reintroduces these patches for\nUbuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases\nand permissions will not be modified on upgrade. To manually restrict\naccess for existing installations, please refer to the following:\n\nhttp://dev.mysql.com/doc/refman/5.5/en/default-privileges.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.10.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.13.10.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0001","CVE-2014-0384","CVE-2014-2419","CVE-2014-2430","CVE-2014-2431","CVE-2014-2432","CVE-2014-2436","CVE-2014-2438","CVE-2014-2440"]}]},{"id":"CVE-2014-2431","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and\n5.6.16 and earlier allows remote attackers to affect availability via\nunknown vectors related to Options.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no indication that 5.1 is vulnerable, and no details, so\nmarking as not-affected for now."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2170-1","https://www.cve.org/CVERecord?id=CVE-2014-2431"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2431","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744910","https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1309662"],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.37-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.37-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.37-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.37-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.37","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.17-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.17","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2170-1"],"notices":[{"id":"USN-2170-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T12:56:46.008447","description":"Multiple security issues were discovered in MySQL and this update includes\na new upstream MySQL version to fix these issues. MySQL has been updated to\n5.5.37.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html\nhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html\n\nAdditionally, Matthias Reichl discovered that the mysql-5.5 packages were\nmissing the patches applied previously in the mysql-5.1 packages to drop\nthe default test database and localhost permissions granting access to any\ndatabases starting with \"test_\". This update reintroduces these patches for\nUbuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases\nand permissions will not be modified on upgrade. To manually restrict\naccess for existing installations, please refer to the following:\n\nhttp://dev.mysql.com/doc/refman/5.5/en/default-privileges.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.10.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.13.10.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0001","CVE-2014-0384","CVE-2014-2419","CVE-2014-2430","CVE-2014-2431","CVE-2014-2432","CVE-2014-2436","CVE-2014-2438","CVE-2014-2440"]}]},{"id":"CVE-2014-2430","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and\n5.6.16 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to Performance Schema.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no indication that 5.1 is vulnerable, and no details, so\nmarking as not-affected for now."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2170-1","https://www.cve.org/CVERecord?id=CVE-2014-2430"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2430","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744910","https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1309662"],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.37-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.37-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.37-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.37-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.37","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.17-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.17","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2170-1"],"notices":[{"id":"USN-2170-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T12:56:46.008447","description":"Multiple security issues were discovered in MySQL and this update includes\na new upstream MySQL version to fix these issues. MySQL has been updated to\n5.5.37.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html\nhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html\n\nAdditionally, Matthias Reichl discovered that the mysql-5.5 packages were\nmissing the patches applied previously in the mysql-5.1 packages to drop\nthe default test database and localhost permissions granting access to any\ndatabases starting with \"test_\". This update reintroduces these patches for\nUbuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases\nand permissions will not be modified on upgrade. To manually restrict\naccess for existing installations, please refer to the following:\n\nhttp://dev.mysql.com/doc/refman/5.5/en/default-privileges.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.10.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.13.10.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0001","CVE-2014-0384","CVE-2014-2419","CVE-2014-2430","CVE-2014-2431","CVE-2014-2432","CVE-2014-2436","CVE-2014-2438","CVE-2014-2440"]}]},{"id":"CVE-2014-2427","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and\nJava SE Embedded 7u51, allows remote attackers to affect confidentiality,\nintegrity, and availability via unknown vectors related to Sound.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-2427"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2423","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE\nEmbedded 7u51, allows remote attackers to affect confidentiality,\nintegrity, and availability via vectors related to JAX-WS, a different\nvulnerability than CVE-2014-0452 and CVE-2014-0458.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-2423"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2421","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8;\nJavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect\nconfidentiality, integrity, and availability via unknown vectors related to\n2D.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-2421"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2419","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and\n5.6.15 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to Partition.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"no indication that 5.1 is vulnerable, and no details, so\nmarking as not-affected for now."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2170-1","https://www.cve.org/CVERecord?id=CVE-2014-2419"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-2419","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744910","https://bugs.launchpad.net/ubuntu/+source/mysql-5.5/+bug/1309662"],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-5.6":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.37-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.37-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.37-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.5.37-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.36","component":null,"pocket":"security"}]},{"name":"mysql-5.6","source":"https://ubuntu.com/security/cve?package=mysql-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.6","debian":"https://tracker.debian.org/pkg/mysql-5.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.16","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.6.16-1~exp1]]","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2170-1"],"notices":[{"id":"USN-2170-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-23T12:56:46.008447","description":"Multiple security issues were discovered in MySQL and this update includes\na new upstream MySQL version to fix these issues. MySQL has been updated to\n5.5.37.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html\nhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html\n\nAdditionally, Matthias Reichl discovered that the mysql-5.5 packages were\nmissing the patches applied previously in the mysql-5.1 packages to drop\nthe default test database and localhost permissions granting access to any\ndatabases starting with \"test_\". This update reintroduces these patches for\nUbuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases\nand permissions will not be modified on upgrade. To manually restrict\naccess for existing installations, please refer to the following:\n\nhttp://dev.mysql.com/doc/refman/5.5/en/default-privileges.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.12.10.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.13.10.1"}],"trusty":[{"name":"mysql-5.5","version":"5.5.37-0ubuntu0.14.04.1","description":"MySQL database","is_source":true},{"name":"libmysqlclient-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqlclient18","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-dev","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"libmysqld-pic","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-client-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-common","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-server-core-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-source-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"},{"name":"mysql-testsuite-5.5","version":"5.5.37-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.37-0ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0001","CVE-2014-0384","CVE-2014-2419","CVE-2014-2430","CVE-2014-2431","CVE-2014-2432","CVE-2014-2436","CVE-2014-2438","CVE-2014-2440"]}]},{"id":"CVE-2014-2414","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE\nEmbedded 7u51, allows remote attackers to affect confidentiality,\nintegrity, and availability via vectors related to JAXB.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-2414"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2413","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE\nEmbedded 7u51, allows remote attackers to affect integrity via unknown\nvectors related to Libraries.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://www.cve.org/CVERecord?id=CVE-2014-2413"],"bugs":[""],"patches":{"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2412","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, SE 7u51, and 8,\nand Java SE Embedded 7u51, allows remote attackers to affect\nconfidentiality, integrity, and availability via vectors related to AWT, a\ndifferent vulnerability than CVE-2014-0451.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-2412"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2403","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE\nEmbedded 7u51, allows remote attackers to affect confidentiality via\nvectors related to JAXP.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-2403"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2402","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE\nEmbedded 7u51, allows remote attackers to affect confidentiality,\nintegrity, and availability via unknown vectors related to Libraries, a\ndifferent vulnerability than CVE-2014-0432 and CVE-2014-0455.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://www.cve.org/CVERecord?id=CVE-2014-2402"],"bugs":[""],"patches":{"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2398","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8;\nJavaFX 2.2.51; and JRockit R27.8.1 and R28.3.1 allows remote authenticated\nusers to affect integrity via unknown vectors related to Javadoc.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-2398"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-2397","published":"2014-04-15T00:00:00","updated_at":"2025-05-26T12:49:12.472311+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE\nEmbedded 7u51, allows remote attackers to affect confidentiality,\nintegrity, and availability via unknown vectors related to Hotspot.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://www.cve.org/CVERecord?id=CVE-2014-2397","https://ubuntu.com/security/notices/USN-2191-1"],"bugs":[""],"patches":{"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]},{"id":"CVE-2014-0461","published":"2014-04-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE\nEmbedded 7u51, allows remote attackers to affect confidentiality,\nintegrity, and availability via unknown vectors related to Libraries.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html","https://ubuntu.com/security/notices/USN-2187-1","https://ubuntu.com/security/notices/USN-2191-1","https://www.cve.org/CVERecord?id=CVE-2014-0461"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b31-1.13.3-1ubuntu1~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b31-1.13.3-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b31-1.13.3-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6b31-1.13.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [6b31-1.13.3-1ubuntu1]]","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u55-2.4.7-1ubuntu1~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u55-2.4.7-1ubuntu1~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u55-2.4.7-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u55-2.4.7-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2187-1","USN-2191-1"],"notices":[{"id":"USN-2187-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-04-30T14:32:48.262207","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-cacao","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.12.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.12.10.1"}],"saucy":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1~0.13.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1~0.13.10.1"}],"trusty":[{"name":"openjdk-7","version":"7u55-2.4.7-1ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"},{"name":"openjdk-7-source","version":"7u55-2.4.7-1ubuntu1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u55-2.4.7-1ubuntu1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]},{"id":"USN-2191-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-05-01T21:03:57.394359","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,\nCVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,\nCVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nA vulnerability was discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b31-1.13.3-1ubuntu1~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b31-1.13.3-1ubuntu1~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-0462","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2403","CVE-2014-2405","CVE-2014-2412","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427"]}]}],"offset":65700,"limit":20,"total_results":79316}