{"cves":[{"id":"CVE-2013-6661","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google Chrome before 33.0.1750.117\nallow attackers to bypass the sandbox protection mechanism after obtaining\nrenderer access, or have other impact, via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=344876","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6661"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6660","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe drag-and-drop implementation in Google Chrome before 33.0.1750.117 does\nnot properly restrict the information in WebDropData data structures, which\nallows remote attackers to discover full pathnames via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=244538&view=revision","https://code.google.com/p/chromium/issues/detail?id=332579","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6660"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6659","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SSLClientSocketNSS::Core::OwnAuthCertHandler function in\nnet/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117\ndoes not prevent changes to server X.509 certificates during\nrenegotiations, which allows remote SSL servers to trigger use of a new\ncertificate chain, inconsistent with the user's expectations, by initiating\na TLS renegotiation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=229611&view=revision","https://code.google.com/p/chromium/issues/detail?id=306959","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6659"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6658","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple use-after-free vulnerabilities in the layout implementation in\nBlink, as used in Google Chrome before 33.0.1750.117, allow remote\nattackers to cause a denial of service or possibly have unspecified other\nimpact via vectors involving (1) running JavaScript code during execution\nof the updateWidgetPositions function or (2) making a call into a plugin\nduring execution of the updateWidgetPositions function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=165052&view=revision","https://code.google.com/p/chromium/issues/detail?id=322891","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6658"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6657","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncore/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in\nGoogle Chrome before 33.0.1750.117, inserts the about:blank URL during\ncertain blocking of FORM elements within HTTP requests, which allows remote\nattackers to bypass the Same Origin Policy and obtain sensitive information\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=164538&view=revision","https://code.google.com/p/chromium/issues/detail?id=331060","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6657"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6656","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS\nauditor in Blink, as used in Google Chrome before 33.0.1750.117, processes\nPOST requests by using the body of a redirecting page instead of the body\nof a redirect target, which allows remote attackers to obtain sensitive\ninformation via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=164749&view=revision","https://code.google.com/p/chromium/issues/detail?id=331725","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6656"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6655","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Blink, as used in Google Chrome before\n33.0.1750.117, allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via vectors related to improper\nhandling of overflowchanged DOM events during interaction between\nJavaScript and layout.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=162655&view=revision","https://code.google.com/p/chromium/issues/detail?id=293534","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6655"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6654","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SVGAnimateElement::calculateAnimatedValue function in\ncore/svg/SVGAnimateElement.cpp in Blink, as used in Google Chrome before\n33.0.1750.117, does not properly handle unexpected data types, which allows\nremote attackers to cause a denial of service (incorrect cast) or possibly\nhave unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=165009&view=revision","https://code.google.com/p/chromium/issues/detail?id=333176","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6654"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6653","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the web contents implementation in Google\nChrome before 33.0.1750.117 allows remote attackers to cause a denial of\nservice or possibly have unspecified other impact via vectors involving\nattempted conflicting access to the color chooser.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=244710&view=revision","https://code.google.com/p/chromium/issues/detail?id=331790","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6653"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"33.0.1750.152-0ubuntu0.12.04.1~pkg879.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"33.0.1750.152-0ubuntu0.12.10.1~pkg895.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"33.0.1750.152-0ubuntu0.13.10.1~pkg984.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6652","published":"2014-02-24T04:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in\nsandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before\n33.0.1750.117 on Windows allows attackers to bypass intended named-pipe\npolicy restrictions in the sandbox via vectors related to (1) lack of\nchecks for .. (dot dot) sequences or (2) lack of use of the \\\\?\\ protection\nmechanism.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"windows-specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=247511&view=revision","https://code.google.com/p/chromium/issues/detail?id=334897","http://googlechromereleases.blogspot.com/2014/02/stable-channel-update_20.html","https://www.cve.org/CVERecord?id=CVE-2013-6652"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"33.0.1750.117","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0502","published":"2014-02-21T05:07:00","updated_at":"2025-08-25T21:11:15.458109+00:00","description":"\nDouble free vulnerability in Adobe Flash Player before 11.7.700.269 and\n11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before\n11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR\nSDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628\nallows remote attackers to execute arbitrary code via unspecified vectors,\nas exploited in the wild in February 2014.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-07.html","https://www.cve.org/CVERecord?id=CVE-2014-0502","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.341-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.341-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.341-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.341","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.341ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.341ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.341ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.341","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0499","published":"2014-02-21T05:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before\n12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe\nAIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and\nAdobe AIR SDK & Compiler before 4.0.0.1628 do not prevent access to address\ninformation, which makes it easier for attackers to bypass the ASLR\nprotection mechanism via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-07.html","https://www.cve.org/CVERecord?id=CVE-2014-0499"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.341-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.341-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.341-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.341","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.341ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.341ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.341ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.341","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-0498","published":"2014-02-21T05:06:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in Adobe Flash Player before 11.7.700.269 and\n11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before\n11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR\nSDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628\nallows attackers to execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://helpx.adobe.com/security/products/flash-player/apsb14-07.html","https://www.cve.org/CVERecord?id=CVE-2014-0498"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.341-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.341-0quantal1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.341-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.341","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.341ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.341ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.341ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.341","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-2030","published":"2014-02-21T00:00:00","updated_at":"2025-08-25T21:15:04.762725+00:00","description":"\nStack-based buffer overflow in the WritePSDImage function in coders/psd.c\nin ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial\nof service (crash) and possibly execute arbitrary code via a crafted PSD\nimage, involving the L%06ld string, a different vulnerability than\nCVE-2014-1947.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same fix as CVE-2014-1947"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2014/02/19/13","https://ubuntu.com/security/notices/USN-2132-1","https://www.cve.org/CVERecord?id=CVE-2014-2030"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1064098","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=740250"],"patches":{"imagemagick":["upstream: http://trac.imagemagick.org/changeset/13736"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"8:6.7.7.10-2ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"8:6.7.7.10-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2132-1"],"notices":[{"id":"USN-2132-1","title":"ImageMagick vulnerabilities","summary":"ImageMagick could be made to crash or run programs if it opened a specially\ncrafted image file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-03-06T19:44:08.184002","description":"Aleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that\nImageMagick incorrectly handled certain restart markers in JPEG images. If\na user or automated system using ImageMagick were tricked into opening a\nspecially crafted JPEG image, an attacker could exploit this to cause\nmemory consumption, resulting in a denial of service. This issue only\naffected Ubuntu 12.04 LTS. (CVE-2012-0260)\n\nIt was discovered that ImageMagick incorrectly handled decoding certain PSD\nimages. If a user or automated system using ImageMagick were tricked into\nopening a specially crafted PSD image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program. (CVE-2014-1958, CVE-2014-2030)\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.3","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.3"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.3"}],"saucy":[{"name":"imagemagick","version":"8:6.7.7.10-5ubuntu3.1","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++5","version":"8:6.7.7.10-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-5ubuntu3.1"},{"name":"libmagickcore5","version":"8:6.7.7.10-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-5ubuntu3.1"}],"quantal":[{"name":"imagemagick","version":"8:6.7.7.10-2ubuntu4.2","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++5","version":"8:6.7.7.10-2ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-2ubuntu4.2"},{"name":"libmagickcore5","version":"8:6.7.7.10-2ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-2ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2012-0260","CVE-2014-1958","CVE-2014-2030"]}]},{"id":"CVE-2014-2015","published":"2014-02-21T00:00:00","updated_at":"2025-09-21T20:06:47.470217+00:00","description":"\nStack-based buffer overflow in the normify function in the rlm_pap module\n(modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier,\nand 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a\ndenial of service (crash) and possibly execute arbitrary code via a long\npassword hash, as demonstrated by an SSHA hash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.freebsd.org/pipermail/freebsd-bugbusters/2014-February/000610.html","https://ubuntu.com/security/notices/USN-2122-1","https://www.cve.org/CVERecord?id=CVE-2014-2015"],"bugs":[""],"patches":{"freeradius":["upstream: https://github.com/FreeRADIUS/freeradius-server/commit/0d606cfc29a.patch"]},"tags":{"freeradius":["fortify-source","stack-protector"]},"packages":[{"name":"freeradius","source":"https://ubuntu.com/security/cve?package=freeradius","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freeradius","debian":"https://tracker.debian.org/pkg/freeradius","statuses":[{"release_codename":"lucid","status":"released","description":"2.1.8+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.1.10+dfsg-3ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.1.12+dfsg-1.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.1.12+dfsg-1.2ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2122-1"],"notices":[{"id":"USN-2122-1","title":"FreeRADIUS vulnerabilities","summary":"Several security issues were fixed in FreeRADIUS.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-02-26T13:07:35.681340","description":"It was discovered that FreeRADIUS incorrectly handled unix authentication.\nA remote user could successfully authenticate with an expired password.\n(CVE-2011-4966)\n\nPierre Carrier discovered that FreeRADIUS incorrectly handled rlm_pap\nhash processing. An authenticated user could use this issue to cause\nFreeRADIUS to crash, resulting in a denial of service, or possibly execute\narbitrary code. The default compiler options for affected releases should\nreduce the vulnerability to a denial of service. (CVE-2014-2015)\n","is_hidden":false,"release_packages":{"precise":[{"name":"freeradius","version":"2.1.10+dfsg-3ubuntu0.12.04.2","description":"a high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.10+dfsg-3ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-3ubuntu0.12.04.2"}],"saucy":[{"name":"freeradius","version":"2.1.12+dfsg-1.2ubuntu5.1","description":"high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.12+dfsg-1.2ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.12+dfsg-1.2ubuntu5.1"}],"lucid":[{"name":"freeradius","version":"2.1.8+dfsg-1ubuntu1.1","description":"a high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.8+dfsg-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.8+dfsg-1ubuntu1.1"}],"quantal":[{"name":"freeradius","version":"2.1.12+dfsg-1.1ubuntu0.1","description":"high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.12+dfsg-1.1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.12+dfsg-1.1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2011-4966","CVE-2014-2015"]}]},{"id":"CVE-2014-1959","published":"2014-02-21T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats\nversion 1 X.509 certificates as intermediate CAs, which allows remote\nattackers to bypass intended restrictions by leveraging a X.509 V1\ncertificate from a trusted CA to issue new certificates.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced by:\nhttps://www.gitorious.org/gnutls/gnutls/commit/60ee8a0eb9975d123002b1cffbefd60a8cd5fae6"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.gitorious.org/gnutls/gnutls/commit/b1abfe3d18","http://gnutls.org/security.html","https://ubuntu.com/security/notices/USN-2121-1","https://www.cve.org/CVERecord?id=CVE-2014-1959"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-1959"],"patches":{"gnutls26":["upstream: https://www.gitorious.org/gnutls/gnutls/commit/b1abfe3d182d68539900092eb42fc62cf1bb7e7c"],"gnutls28":["upstream: https://www.gitorious.org/gnutls/gnutls/commit/b1abfe3d182d68539900092eb42fc62cf1bb7e7c"]},"tags":{},"packages":[{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"lucid","status":"not-affected","description":"2.8.5-2ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.12.14-5ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.12.14-5ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.12.23-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.12.23-12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2.12.23-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.12.23-12ubuntu1","component":null,"pocket":"security"}]},{"name":"gnutls28","source":"https://ubuntu.com/security/cve?package=gnutls28","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls28","debian":"https://tracker.debian.org/pkg/gnutls28","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.11-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.2.11-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.2.11-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.2.11-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.2.11-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.2.11-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.2.11-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.2.11-2ubuntu1]","component":null,"pocket":"security"}]}],"notices_ids":["USN-2121-1"],"notices":[{"id":"USN-2121-1","title":"GnuTLS vulnerability","summary":"GnuTLS incorrectly validated certain intermediate certificates.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-02-25T16:35:44.724281","description":"Suman Jana discovered that GnuTLS incorrectly handled version 1\nintermediate certificates. This resulted in them being considered to be a\nvalid CA certificate by default, which was contrary to documented\nbehaviour.\n","is_hidden":false,"release_packages":{"precise":[{"name":"gnutls26","version":"2.12.14-5ubuntu3.6","description":"GNU TLS library","is_source":true},{"name":"libgnutls26","version":"2.12.14-5ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.14-5ubuntu3.6"}],"saucy":[{"name":"gnutls26","version":"2.12.23-1ubuntu4.1","description":"GNU TLS library","is_source":true},{"name":"libgnutls26","version":"2.12.23-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-1ubuntu4.1"}],"quantal":[{"name":"gnutls26","version":"2.12.14-5ubuntu4.5","description":"GNU TLS library","is_source":true},{"name":"libgnutls26","version":"2.12.14-5ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.14-5ubuntu4.5"}]},"type":"USN","cves_ids":["CVE-2014-1959"]}]},{"id":"CVE-2014-1958","published":"2014-02-21T00:00:00","updated_at":"2025-08-25T21:14:58.685605+00:00","description":"\nBuffer overflow in the DecodePSDPixels function in coders/psd.c in\nImageMagick before 6.8.8-5 might allow remote attackers to execute\narbitrary code via a crafted PSD image, involving the L%06ld string, a\ndifferent vulnerability than CVE-2014-2030.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://secunia.com/advisories/56844/","http://www.openwall.com/lists/oss-security/2014/02/13/5","https://ubuntu.com/security/notices/USN-2132-1","https://www.cve.org/CVERecord?id=CVE-2014-1958"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1067276","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=740250"],"patches":{"imagemagick":["upstream: http://trac.imagemagick.org/changeset/14801"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"8:6.7.7.10-2ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"8:6.7.7.10-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2132-1"],"notices":[{"id":"USN-2132-1","title":"ImageMagick vulnerabilities","summary":"ImageMagick could be made to crash or run programs if it opened a specially\ncrafted image file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-03-06T19:44:08.184002","description":"Aleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that\nImageMagick incorrectly handled certain restart markers in JPEG images. If\na user or automated system using ImageMagick were tricked into opening a\nspecially crafted JPEG image, an attacker could exploit this to cause\nmemory consumption, resulting in a denial of service. This issue only\naffected Ubuntu 12.04 LTS. (CVE-2012-0260)\n\nIt was discovered that ImageMagick incorrectly handled decoding certain PSD\nimages. If a user or automated system using ImageMagick were tricked into\nopening a specially crafted PSD image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program. (CVE-2014-1958, CVE-2014-2030)\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.3","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.3"},{"name":"libmagickcore4","version":"8:6.6.9.7-5ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.3"}],"saucy":[{"name":"imagemagick","version":"8:6.7.7.10-5ubuntu3.1","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++5","version":"8:6.7.7.10-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-5ubuntu3.1"},{"name":"libmagickcore5","version":"8:6.7.7.10-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-5ubuntu3.1"}],"quantal":[{"name":"imagemagick","version":"8:6.7.7.10-2ubuntu4.2","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++5","version":"8:6.7.7.10-2ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-2ubuntu4.2"},{"name":"libmagickcore5","version":"8:6.7.7.10-2ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-2ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2012-0260","CVE-2014-1958","CVE-2014-2030"]}]},{"id":"CVE-2014-1933","published":"2014-02-21T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python\nImage Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the\nnames of temporary files on the command line, which makes it easier for\nlocal users to conduct symlink attacks by listing the processes.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"See also CVE-2014-1932"},{"author":"mdeslaur","note":"same patch as CVE-2014-1932"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2168-1","https://www.cve.org/CVERecord?id=CVE-2014-1933"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737059"],"patches":{"pillow":[],"python-imaging":["upstream: https://github.com/wiredfool/Pillow/commit/a549e77bd8219a75ac745dcecc09cb963b4032a6","upstream: https://github.com/wiredfool/Pillow/commit/1e331e3e6a40141ca8eee4f5da9f74e895423b66"]},"tags":{},"packages":[{"name":"pillow","source":"https://ubuntu.com/security/cve?package=pillow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pillow","debian":"https://tracker.debian.org/pkg/pillow","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python-imaging","source":"https://ubuntu.com/security/cve?package=python-imaging","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-imaging","debian":"https://tracker.debian.org/pkg/python-imaging","statuses":[{"release_codename":"lucid","status":"released","description":"1.1.7-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.1.7-4ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.1.7-4ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.1.7+2.0.0-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2168-1"],"notices":[{"id":"USN-2168-1","title":"Python Imaging Library vulnerabilities","summary":"Python Imaging Library could be made to overwrite or expose files.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-15T14:17:44.987934","description":"Jakub Wilk discovered that the Python Imaging Library incorrectly handled\ntemporary files. A local attacker could possibly use this issue to\noverwrite arbitrary files, or gain access to temporary file contents.\n(CVE-2014-1932, CVE-2014-1933)\n","is_hidden":false,"release_packages":{"precise":[{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.04.1","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7-4ubuntu0.12.04.1"}],"saucy":[{"name":"python-imaging","version":"1.1.7+2.0.0-1ubuntu1.1","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7+2.0.0-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7+2.0.0-1ubuntu1.1"}],"lucid":[{"name":"python-imaging","version":"1.1.7-1ubuntu0.2","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7-1ubuntu0.2"}],"quantal":[{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.10.1","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7-4ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1932","CVE-2014-1933"]}]},{"id":"CVE-2014-1932","published":"2014-02-21T00:00:00","updated_at":"2025-09-21T20:04:43.480830+00:00","description":"\nThe (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function\nin EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4)\n_copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier\nand Pillow before 2.3.1 do not properly create temporary files, which allow\nlocal users to overwrite arbitrary files and obtain sensitive information\nvia a symlink attack on the temporary file.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Normally mktemp() mistakes are classed as 'low' because Ubuntu has\nhardlink and symlink protections in the kernel. However, one of the discovered\nflaws is almost certainly also a shell metacharacter injection problem."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2168-1","https://www.cve.org/CVERecord?id=CVE-2014-1932"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737059"],"patches":{"pillow":[],"python-imaging":["upstream: https://github.com/wiredfool/Pillow/commit/a549e77bd8219a75ac745dcecc09cb963b4032a6","upstream: https://github.com/wiredfool/Pillow/commit/1e331e3e6a40141ca8eee4f5da9f74e895423b66"]},"tags":{"pillow":["symlink-restriction","hardlink-restriction"]},"packages":[{"name":"pillow","source":"https://ubuntu.com/security/cve?package=pillow","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pillow","debian":"https://tracker.debian.org/pkg/pillow","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python-imaging","source":"https://ubuntu.com/security/cve?package=python-imaging","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-imaging","debian":"https://tracker.debian.org/pkg/python-imaging","statuses":[{"release_codename":"lucid","status":"released","description":"1.1.7-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.1.7-4ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.1.7-4ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.1.7+2.0.0-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2168-1"],"notices":[{"id":"USN-2168-1","title":"Python Imaging Library vulnerabilities","summary":"Python Imaging Library could be made to overwrite or expose files.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-04-15T14:17:44.987934","description":"Jakub Wilk discovered that the Python Imaging Library incorrectly handled\ntemporary files. A local attacker could possibly use this issue to\noverwrite arbitrary files, or gain access to temporary file contents.\n(CVE-2014-1932, CVE-2014-1933)\n","is_hidden":false,"release_packages":{"precise":[{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.04.1","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7-4ubuntu0.12.04.1"}],"saucy":[{"name":"python-imaging","version":"1.1.7+2.0.0-1ubuntu1.1","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7+2.0.0-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7+2.0.0-1ubuntu1.1"}],"lucid":[{"name":"python-imaging","version":"1.1.7-1ubuntu0.2","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7-1ubuntu0.2"}],"quantal":[{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.10.1","description":"Python Imaging Library","is_source":true},{"name":"python-imaging","version":"1.1.7-4ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python-imaging","version_link":"https://launchpad.net/ubuntu/+source/python-imaging/1.1.7-4ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2014-1932","CVE-2014-1933"]}]},{"id":"CVE-2014-1912","published":"2014-02-21T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the socket.recvfrom_into function in\nModules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and\n3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a\ncrafted string.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.trustedsec.com/february-2014/python-remote-code-execution-socket-recvfrom_into/","https://ubuntu.com/security/notices/USN-2125-1","https://www.cve.org/CVERecord?id=CVE-2014-1912"],"bugs":["http://bugs.python.org/issue20246"],"patches":{"python2.7":["upstream: http://hg.python.org/cpython/rev/87673659d8f7"],"python2.6":[],"python3.4":[],"python3.2":["upstream: http://hg.python.org/cpython/rev/9c56217e5c79"],"python3.3":["upstream: http://hg.python.org/cpython/rev/7f176a45211f"],"python3.1":["upstream: http://hg.python.org/cpython/rev/715fd3d8ac93"]},"tags":{},"packages":[{"name":"python2.6","source":"https://ubuntu.com/security/cve?package=python2.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.6","debian":"https://tracker.debian.org/pkg/python2.6","statuses":[{"release_codename":"lucid","status":"released","description":"2.6.5-1ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.3-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.7.3-5ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.7.5-8ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"python3.1","source":"https://ubuntu.com/security/cve?package=python3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.1","debian":"https://tracker.debian.org/pkg/python3.1","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python3.2","source":"https://ubuntu.com/security/cve?package=python3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.2","debian":"https://tracker.debian.org/pkg/python3.2","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.3-0ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.2.3-6ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python3.3","source":"https://ubuntu.com/security/cve?package=python3.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.3","debian":"https://tracker.debian.org/pkg/python3.3","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.3.0-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"3.3.2-7ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python3.4","source":"https://ubuntu.com/security/cve?package=python3.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.4","debian":"https://tracker.debian.org/pkg/python3.4","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2125-1"],"notices":[{"id":"USN-2125-1","title":"Python vulnerability","summary":"Python could be made to crash or run programs if it received specially\ncrafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-03-03T17:51:38.411692","description":"Ryan Smith-Roberts discovered that Python incorrectly handled buffer sizes\nwhen using the socket.recvfrom_into() function. An attacker could possibly\nuse this issue to cause Python to crash, resulting in denial of service, or\npossibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"python2.7","version":"2.7.3-0ubuntu3.5","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.2","version":"3.2.3-0ubuntu3.6","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.7","version":"2.7.3-0ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.3-0ubuntu3.5"},{"name":"python2.7-minimal","version":"2.7.3-0ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.3-0ubuntu3.5"},{"name":"python3.2","version":"3.2.3-0ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.2","version_link":"https://launchpad.net/ubuntu/+source/python3.2/3.2.3-0ubuntu3.6"},{"name":"python3.2-minimal","version":"3.2.3-0ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.2","version_link":"https://launchpad.net/ubuntu/+source/python3.2/3.2.3-0ubuntu3.6"}],"saucy":[{"name":"python2.7","version":"2.7.5-8ubuntu3.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.3","version":"3.3.2-7ubuntu3.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.7-minimal","version":"2.7.5-8ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.5-8ubuntu3.1"},{"name":"python3.3-minimal","version":"3.3.2-7ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.3","version_link":"https://launchpad.net/ubuntu/+source/python3.3/3.3.2-7ubuntu3.1"},{"name":"python2.7","version":"2.7.5-8ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.5-8ubuntu3.1"},{"name":"python3.3","version":"3.3.2-7ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.3","version_link":"https://launchpad.net/ubuntu/+source/python3.3/3.3.2-7ubuntu3.1"}],"lucid":[{"name":"python2.6","version":"2.6.5-1ubuntu6.3","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.6-minimal","version":"2.6.5-1ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.5-1ubuntu6.3"},{"name":"python2.6","version":"2.6.5-1ubuntu6.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.6","version_link":"https://launchpad.net/ubuntu/+source/python2.6/2.6.5-1ubuntu6.3"}],"quantal":[{"name":"python2.7","version":"2.7.3-5ubuntu4.4","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.2","version":"3.2.3-6ubuntu3.5","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.3","version":"3.3.0-1ubuntu0.2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.3-minimal","version":"3.3.0-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.3","version_link":"https://launchpad.net/ubuntu/+source/python3.3/3.3.0-1ubuntu0.2"},{"name":"python2.7","version":"2.7.3-5ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.3-5ubuntu4.4"},{"name":"python2.7-minimal","version":"2.7.3-5ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.3-5ubuntu4.4"},{"name":"python3.2","version":"3.2.3-6ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.2","version_link":"https://launchpad.net/ubuntu/+source/python3.2/3.2.3-6ubuntu3.5"},{"name":"python3.3","version":"3.3.0-1ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.3","version_link":"https://launchpad.net/ubuntu/+source/python3.3/3.3.0-1ubuntu0.2"},{"name":"python3.2-minimal","version":"3.2.3-6ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.2","version_link":"https://launchpad.net/ubuntu/+source/python3.2/3.2.3-6ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2014-1912"]}]}],"offset":66040,"limit":20,"total_results":79316}