{"cves":[{"id":"CVE-2014-0428","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE\nEmbedded 7u45; and OpenJDK 7 allows remote attackers to affect\nconfidentiality, integrity, and availability via vectors related to CORBA.\nNOTE: the previous information is from the January 2014 CPU. Oracle has not\ncommented on third-party claims that the issue is related to \"insufficient\nsecurity checks in IIOP streams,\" which allows attackers to escape the\nsandbox.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0428"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2014-0423","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit\nR27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote\nauthenticated users to affect confidentiality and availability via unknown\nvectors related to Beans. NOTE: the previous information is from the\nJanuary 2014 CPU. Oracle has not commented on third-party claims that this\nissue is an XML External Entity (XXE) vulnerability in\nDocumentHandler.java, related to Beans decoding.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0423"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2014-0422","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE\nEmbedded 7u45; and OpenJDK 7 allows remote attackers to affect\nconfidentiality, integrity, and availability via vectors related to JNDI.\nNOTE: the previous information is from the January 2014 CPU. Oracle has not\ncommented on third-party claims that the issue is related to missing\npackage access checks in the Naming / JNDI component, which allows\nattackers to escape the sandbox.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0422"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2014-0420","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.5.34 and earlier, and 5.6.14 and earlier, allows remote authenticated\nusers to affect availability via unknown vectors related to Replication.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"5.6 and 5.5 only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2086-1","https://www.cve.org/CVERecord?id=CVE-2014-0420"],"bugs":[""],"patches":{"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.35-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.35-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.35-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.35","component":null,"pocket":"security"}]}],"notices_ids":["USN-2086-1"],"notices":[{"id":"USN-2086-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-01-21T13:54:05.615494","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,\nUbuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.04.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.13.10.1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.73-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.73-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.73-0ubuntu0.10.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-5891","CVE-2013-5908","CVE-2014-0386","CVE-2014-0393","CVE-2014-0401","CVE-2014-0402","CVE-2014-0412","CVE-2014-0420","CVE-2014-0437"]}]},{"id":"CVE-2014-0416","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE\nEmbedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity\nvia vectors related to JAAS. NOTE: the previous information is from the\nJanuary 2014 CPU. Oracle has not commented on third-party claims that the\nissue is related to how principals are set for the Subject class, which\nallows attackers to escape the sandbox using deserialization of a crafted\nSubject instance.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0416"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2014-0412","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows\nremote authenticated users to affect availability via unknown vectors\nrelated to InnoDB.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2086-1","https://www.cve.org/CVERecord?id=CVE-2014-0412"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.35-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.35-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.35-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.35","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"released","description":"5.1.73-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.73","component":null,"pocket":"security"}]}],"notices_ids":["USN-2086-1"],"notices":[{"id":"USN-2086-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-01-21T13:54:05.615494","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,\nUbuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.04.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.13.10.1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.73-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.73-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.73-0ubuntu0.10.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-5891","CVE-2013-5908","CVE-2014-0386","CVE-2014-0393","CVE-2014-0401","CVE-2014-0402","CVE-2014-0412","CVE-2014-0420","CVE-2014-0437"]}]},{"id":"CVE-2014-0411","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit\nR27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote\nattackers to affect confidentiality and integrity via vectors related to\nJSSE. NOTE: the previous information is from the January 2014 CPU. Oracle\nhas not commented on third-party claims that this issue allows remote\nattackers to obtain sensitive information about encryption keys via a\ntiming discrepancy during the TLS/SSL handshake.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0411"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2014-0402","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows\nremote authenticated users to affect availability via unknown vectors\nrelated to Locking.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2086-1","https://www.cve.org/CVERecord?id=CVE-2014-0402"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.35-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.35-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.35-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.34","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"released","description":"5.1.73-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.72","component":null,"pocket":"security"}]}],"notices_ids":["USN-2086-1"],"notices":[{"id":"USN-2086-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-01-21T13:54:05.615494","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,\nUbuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.04.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.13.10.1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.73-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.73-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.73-0ubuntu0.10.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-5891","CVE-2013-5908","CVE-2014-0386","CVE-2014-0393","CVE-2014-0401","CVE-2014-0402","CVE-2014-0412","CVE-2014-0420","CVE-2014-0437"]}]},{"id":"CVE-2014-0401","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows\nremote authenticated users to affect availability via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2086-1","https://www.cve.org/CVERecord?id=CVE-2014-0401"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.35-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.35-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.35-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.35","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"released","description":"5.1.73-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.73","component":null,"pocket":"security"}]}],"notices_ids":["USN-2086-1"],"notices":[{"id":"USN-2086-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-01-21T13:54:05.615494","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,\nUbuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.04.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.13.10.1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.73-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.73-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.73-0ubuntu0.10.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-5891","CVE-2013-5908","CVE-2014-0386","CVE-2014-0393","CVE-2014-0401","CVE-2014-0402","CVE-2014-0412","CVE-2014-0420","CVE-2014-0437"]}]},{"id":"CVE-2014-0393","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows\nremote authenticated users to affect integrity via unknown vectors related\nto InnoDB.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2086-1","https://www.cve.org/CVERecord?id=CVE-2014-0393"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.35-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.35-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.35-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.34","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"released","description":"5.1.73-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.72","component":null,"pocket":"security"}]}],"notices_ids":["USN-2086-1"],"notices":[{"id":"USN-2086-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-01-21T13:54:05.615494","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,\nUbuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.04.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.13.10.1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.73-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.73-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.73-0ubuntu0.10.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-5891","CVE-2013-5908","CVE-2014-0386","CVE-2014-0393","CVE-2014-0401","CVE-2014-0402","CVE-2014-0412","CVE-2014-0420","CVE-2014-0437"]}]},{"id":"CVE-2014-0386","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows\nremote authenticated users to affect availability via unknown vectors\nrelated to Optimizer.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2086-1","https://www.cve.org/CVERecord?id=CVE-2014-0386"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.35-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.35-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.35-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.34","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"released","description":"5.1.73-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.72","component":null,"pocket":"security"}]}],"notices_ids":["USN-2086-1"],"notices":[{"id":"USN-2086-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-01-21T13:54:05.615494","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,\nUbuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.04.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.13.10.1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.73-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.73-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.73-0ubuntu0.10.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-5891","CVE-2013-5908","CVE-2014-0386","CVE-2014-0393","CVE-2014-0401","CVE-2014-0402","CVE-2014-0412","CVE-2014-0420","CVE-2014-0437"]}]},{"id":"CVE-2014-0376","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE\nEmbedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity\nvia vectors related to JAXP. NOTE: the previous information is from the\nJanuary 2014 CPU. Oracle has not commented on third-party claims that the\nissue is related to an improper check for \"code permissions when creating\ndocument builder factories.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0376"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2014-0373","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and\nOpenJDK 7, allows remote attackers to affect confidentiality, integrity,\nand availability via unknown vectors related to Serviceability. NOTE: the\nprevious information is from the January 2014 CPU. Oracle has not commented\non third-party claims that the issue is related to throwing of an incorrect\nexception when SnmpStatusException should have been used in the SNMP\nimplementation, which allows attackers to escape the sandbox.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0373"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2014-0368","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and\nJava SE Embedded 7u45, allows remote attackers to affect confidentiality\nvia unknown vectors related to Networking. NOTE: the previous information\nis from the January 2014 CPU. Oracle has not commented on third-party\nclaims that the issue is related to incorrect permission checks when\nlistening on a socket, which allows attackers to escape the sandbox.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2014-0368"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2013-7205","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the process_cgivars function in contrib/daemonchk.c in\nNagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to\nobtain sensitive information from process memory or cause a denial of\nservice (crash) via a long string in the last key value in the variable\nlist, which triggers a heap-based buffer over-read.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"nagios fix had an additional source file, so this CVE was\nsplit out from CVE-2013-7108. (contrib/daemonchk.c)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3253-1","https://www.cve.org/CVERecord?id=CVE-2013-7205"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771466"],"patches":{"nagios3":["upstream: http://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/","upstream: https://sourceforge.net/p/nagios/nagioscore/ci/0e733d40f8abf09bd0c0e51c2102964fc2331e97/"]},"tags":{},"packages":[{"name":"nagios3","source":"https://ubuntu.com/security/cve?package=nagios3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nagios3","debian":"https://tracker.debian.org/pkg/nagios3","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.1.dfsg-2.1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"3.5.1.dfsg-2.1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"3.5.1.dfsg-2.1ubuntu5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.5.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3253-1"],"notices":[{"id":"USN-3253-1","title":"Nagios vulnerabilities","summary":"Several security issues were fixed in Nagios.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-04-03T17:42:28.112003","description":"It was discovered that Nagios incorrectly handled certain long strings. A\nremote authenticated attacker could use this issue to cause Nagios to\ncrash, resulting in a denial of service, or possibly obtain sensitive\ninformation. (CVE-2013-7108, CVE-2013-7205)\n\nIt was discovered that Nagios incorrectly handled certain long messages to\ncmd.cgi. A remote attacker could possibly use this issue to cause Nagios to\ncrash, resulting in a denial of service. (CVE-2014-1878)\n\nDawid Golunski discovered that Nagios incorrectly handled symlinks when\naccessing log files. A local attacker could possibly use this issue to\nelevate privileges. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2016-9566)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"nagios3","version":"3.5.1-1ubuntu1.1","description":"host/service/network monitoring and management system","is_source":true},{"name":"nagios3","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-cgi","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-common","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-core","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-doc","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"}],"xenial":[{"name":"nagios3","version":"3.5.1.dfsg-2.1ubuntu1.1","description":"host/service/network monitoring and management system","is_source":true},{"name":"nagios3","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-cgi","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-common","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-core","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-doc","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"}],"yakkety":[{"name":"nagios3","version":"3.5.1.dfsg-2.1ubuntu3.1","description":"host/service/network monitoring and management system","is_source":true},{"name":"nagios3-cgi","version":"3.5.1.dfsg-2.1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu3.1"},{"name":"nagios3-core","version":"3.5.1.dfsg-2.1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2013-7108","CVE-2013-7205","CVE-2014-1878","CVE-2016-9566"]}]},{"id":"CVE-2013-7108","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and\nIcinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote\nauthenticated users to obtain sensitive information from process memory or\ncause a denial of service (crash) via a long string in the last key value\nin the variable list to the process_cgivars function in (1) avail.c, (2)\ncmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c,\n(7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11)\ntrends.c in cgi/, which triggers a heap-based buffer over-read.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://dev.icinga.org/issues/5251","https://ubuntu.com/security/notices/USN-3253-1","https://www.cve.org/CVERecord?id=CVE-2013-7108"],"bugs":["https://dev.icinga.org/issues/5251","https://bugs.launchpad.net/bugs/1279826","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771466"],"patches":{"nagios3":["upstream: http://sourceforge.net/p/nagios/nagioscore/ci/d97e03f32741a7d851826b03ed73ff4c9612a866/","upstream: https://sourceforge.net/p/nagios/nagioscore/ci/0e733d40f8abf09bd0c0e51c2102964fc2331e97/"],"icinga":[]},"tags":{},"packages":[{"name":"icinga","source":"https://ubuntu.com/security/cve?package=icinga","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icinga","debian":"https://tracker.debian.org/pkg/icinga","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.2-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.10.2-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.10.2-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.10.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.10.2-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.10.2-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.10.2-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.10.2-1]","component":null,"pocket":"security"}]},{"name":"nagios3","source":"https://ubuntu.com/security/cve?package=nagios3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nagios3","debian":"https://tracker.debian.org/pkg/nagios3","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.5.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.1.dfsg-2.1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"3.5.1.dfsg-2.1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"3.5.1.dfsg-2.1ubuntu5","component":null,"pocket":"security"}]}],"notices_ids":["USN-3253-1"],"notices":[{"id":"USN-3253-1","title":"Nagios vulnerabilities","summary":"Several security issues were fixed in Nagios.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-04-03T17:42:28.112003","description":"It was discovered that Nagios incorrectly handled certain long strings. A\nremote authenticated attacker could use this issue to cause Nagios to\ncrash, resulting in a denial of service, or possibly obtain sensitive\ninformation. (CVE-2013-7108, CVE-2013-7205)\n\nIt was discovered that Nagios incorrectly handled certain long messages to\ncmd.cgi. A remote attacker could possibly use this issue to cause Nagios to\ncrash, resulting in a denial of service. (CVE-2014-1878)\n\nDawid Golunski discovered that Nagios incorrectly handled symlinks when\naccessing log files. A local attacker could possibly use this issue to\nelevate privileges. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2016-9566)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"nagios3","version":"3.5.1-1ubuntu1.1","description":"host/service/network monitoring and management system","is_source":true},{"name":"nagios3","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-cgi","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-common","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-core","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"},{"name":"nagios3-doc","version":"3.5.1-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1-1ubuntu1.1","pocket":"security"}],"xenial":[{"name":"nagios3","version":"3.5.1.dfsg-2.1ubuntu1.1","description":"host/service/network monitoring and management system","is_source":true},{"name":"nagios3","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-cgi","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-common","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-core","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"},{"name":"nagios3-doc","version":"3.5.1.dfsg-2.1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu1.1","pocket":"security"}],"yakkety":[{"name":"nagios3","version":"3.5.1.dfsg-2.1ubuntu3.1","description":"host/service/network monitoring and management system","is_source":true},{"name":"nagios3-cgi","version":"3.5.1.dfsg-2.1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu3.1"},{"name":"nagios3-core","version":"3.5.1.dfsg-2.1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nagios3","version_link":"https://launchpad.net/ubuntu/+source/nagios3/3.5.1.dfsg-2.1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2013-7108","CVE-2013-7205","CVE-2014-1878","CVE-2016-9566"]}]},{"id":"CVE-2013-5910","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 6u65 and 7u45, Java SE Embedded\n7u45, and OpenJDK 7 allows remote attackers to affect integrity via unknown\nvectors related to Security. NOTE: the previous information is from the\nJanuary 2014 CPU. Oracle has not commented on third-party claims that\nCanonicalizerBase.java in the XML canonicalizer allows untrusted code to\naccess mutable byte arrays.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2013-5910"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2013-5908","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows\nremote attackers to affect availability via unknown vectors related to\nError Handling.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2086-1","https://www.cve.org/CVERecord?id=CVE-2013-5908"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.35-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.35-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"5.5.35-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.35","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"released","description":"5.1.73-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.73","component":null,"pocket":"security"}]}],"notices_ids":["USN-2086-1"],"notices":[{"id":"USN-2086-1","title":"MySQL vulnerabilities","summary":"Several security issues were fixed in MySQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-01-21T13:54:05.615494","description":"Multiple security issues were discovered in MySQL and this update includes\nnew upstream MySQL versions to fix these issues.\n\nMySQL has been updated to 5.1.73 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,\nUbuntu 12.10, and Ubuntu 13.10 have been updated to MySQL 5.5.35.\n\nIn addition to security fixes, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n\nPlease see the following for more information:\nhttp://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-73.html\nhttp://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-35.html\nhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html\n","is_hidden":false,"release_packages":{"precise":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.04.1"}],"saucy":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.13.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.13.10.1"}],"lucid":[{"name":"mysql-dfsg-5.1","version":"5.1.73-0ubuntu0.10.04.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.1","version":"5.1.73-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1","version_link":"https://launchpad.net/ubuntu/+source/mysql-dfsg-5.1/5.1.73-0ubuntu0.10.04.1"}],"quantal":[{"name":"mysql-5.5","version":"5.5.35-0ubuntu0.12.10.1","description":"MySQL database","is_source":true},{"name":"mysql-server-5.5","version":"5.5.35-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/mysql-5.5","version_link":"https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.35-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-5891","CVE-2013-5908","CVE-2014-0386","CVE-2014-0393","CVE-2014-0401","CVE-2014-0402","CVE-2014-0412","CVE-2014-0420","CVE-2014-0437"]}]},{"id":"CVE-2013-5907","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit\nR27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote\nattackers to affect confidentiality, integrity, and availability via\nunknown vectors related to 2D. NOTE: the previous information is from the\nJanuary 2014 CPU. Oracle has not commented on third-party claims that the\nissue is due to incorrect input validation in LookupProcessor.cpp in the\nICU Layout Engine, which allows attackers to cause a denial of service\n(crash) or possibly execute arbitrary code via a crafted font file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2013-5907"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]},{"id":"CVE-2013-5896","published":"2014-01-15T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE\nEmbedded 7u45; and OpenJDK 7 allows remote attackers to affect availability\nvia vectors related to CORBA. NOTE: the previous information is from the\nJanuary 2014 CPU. Oracle has not commented on third-party claims that\ncom.sun.corba.se and its sub-packages are not included on the restricted\npackage list.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in lucid+, NetX and the plugin moved to the icedtea-web package"},{"author":"jdstrand","note":"sun-java6 is not redistributable, no longer in the archive and\nno longer tracked\nsun-java5 is EOL upstream and no longer tracked"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2014-0026.html","http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","https://ubuntu.com/security/notices/USN-2089-1","https://ubuntu.com/security/notices/USN-2124-1","https://www.cve.org/CVERecord?id=CVE-2013-5896"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"lucid","status":"released","description":"6b30-1.13.1-1ubuntu2~0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b30-1.13.1-1ubuntu2~0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"6b30-1.13.1-1ubuntu2~0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u51-2.4.4-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u51-2.4.4-0ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"7u51-2.4.4-0ubuntu0.13.04.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"7u51-2.4.4-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u51-2.4.4-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2089-1","USN-2124-1"],"notices":[{"id":"USN-2089-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2014-01-23T20:58:26.167195","description":"\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,\nCVE-2013-5804, CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,\nCVE-2013-5910)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,\nCVE-2013-5820, CVE-2014-0376, CVE-2014-0416)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5778, CVE-2013-5780, CVE-2013-5790,\nCVE-2013-5800, CVE-2013-5840, CVE-2013-5849, CVE-2013-5851, CVE-2013-5884,\nCVE-2014-0368)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5782, CVE-2013-5802, CVE-2013-5809, CVE-2013-5829,\nCVE-2013-5814, CVE-2013-5817, CVE-2013-5830, CVE-2013-5842, CVE-2013-5850,\nCVE-2013-5878, CVE-2013-5893, CVE-2013-5907, CVE-2014-0373, CVE-2014-0408,\nCVE-2014-0422, CVE-2014-0428)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.10.1"}],"quantal":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.12.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"icedtea-7-jre-cacao","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.12.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.12.10.2"}],"raring":[{"name":"openjdk-7","version":"7u51-2.4.4-0ubuntu0.13.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-zero","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"icedtea-7-jre-jamvm","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre-headless","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"},{"name":"openjdk-7-jre","version":"7u51-2.4.4-0ubuntu0.13.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u51-2.4.4-0ubuntu0.13.04.2"}]},"type":"USN","cves_ids":["CVE-2013-5817","CVE-2013-5820","CVE-2013-5823","CVE-2013-5825","CVE-2013-5829","CVE-2013-5830","CVE-2013-5840","CVE-2013-5842","CVE-2013-5849","CVE-2013-5850","CVE-2013-5851","CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428","CVE-2014-0408","CVE-2013-5806","CVE-2013-5800","CVE-2013-5805","CVE-2013-5893","CVE-2013-3829","CVE-2013-4002","CVE-2013-5772","CVE-2013-5774","CVE-2013-5778","CVE-2013-5780","CVE-2013-5782","CVE-2013-5783","CVE-2013-5784","CVE-2013-5790","CVE-2013-5797","CVE-2013-5802","CVE-2013-5803","CVE-2013-5804","CVE-2013-5809","CVE-2013-5814"]},{"id":"USN-2124-1","title":"OpenJDK 6 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 6.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":["https://launchpad.net/bugs/1283828"],"published":"2014-02-27T19:07:00.829209","description":"A vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to expose\nsensitive data over the network. (CVE-2014-0411)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,\nCVE-2014-0428)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure. An attacker could exploit these to expose sensitive\ndata over the network. (CVE-2013-5884, CVE-2014-0368)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\navailability. An attacker could exploit these to cause a denial of service.\n(CVE-2013-5896, CVE-2013-5910)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-0376, CVE-2014-0416)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and availability. An attacker could exploit this to expose\nsensitive data over the network or cause a denial of service.\n(CVE-2014-0423)\n\nIn addition to the above, USN-2033-1 fixed several vulnerabilities and bugs\nin OpenJDK 6. This update introduced a regression which caused an exception\ncondition in javax.xml when instantiating encryption algorithms. This\nupdate fixes the problem. We apologize for the inconvenience.\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.12.04.1"}],"lucid":[{"name":"openjdk-6","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b30-1.13.1-1ubuntu2~0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b30-1.13.1-1ubuntu2~0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2013-5878","CVE-2013-5884","CVE-2013-5896","CVE-2013-5907","CVE-2013-5910","CVE-2014-0368","CVE-2014-0373","CVE-2014-0376","CVE-2014-0411","CVE-2014-0416","CVE-2014-0422","CVE-2014-0423","CVE-2014-0428"]}]}],"offset":66320,"limit":20,"total_results":79316}