{"cves":[{"id":"CVE-2013-5606","published":"2013-11-14T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network\nSecurity Services (NSS) 3.15 before 3.15.3 provides an unexpected return\nvalue for an incompatible key-usage certificate when the CERTVerifyLog\nargument is valid, which might allow remote attackers to bypass intended\naccess restrictions via a crafted certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2030-1","https://www.cve.org/CVERecord?id=CVE-2013-5606"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=910438"],"patches":{"nss":[]},"tags":{},"packages":[{"name":"nss","source":"https://ubuntu.com/security/cve?package=nss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nss","debian":"https://tracker.debian.org/pkg/nss","statuses":[{"release_codename":"lucid","status":"released","description":"3.15.3-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.15.3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.15.3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2:3.15.3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2:3.15.3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-2030-1"],"notices":[{"id":"USN-2030-1","title":"NSS vulnerabilities","summary":"Several security issues were fixed in NSS.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use NSS, such as Evolution and Chromium, to make all the necessary\nchanges.\n","references":[],"published":"2013-11-18T20:12:06.225636","description":"Multiple security issues were discovered in NSS. If a user were tricked\ninto connecting to a malicious server, an attacker could possibly exploit\nthese to cause a denial of service via application crash, potentially\nexecute arbitrary code, or lead to information disclosure.\n\nThis update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04\nLTS, Ubuntu 12.10, and Ubuntu 13.04.\n","is_hidden":false,"release_packages":{"precise":[{"name":"nss","version":"3.15.3-0ubuntu0.12.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"3.15.3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.12.04.1"}],"saucy":[{"name":"nss","version":"2:3.15.3-0ubuntu0.13.10.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.15.3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.15.3-0ubuntu0.13.10.1"}],"lucid":[{"name":"nss","version":"3.15.3-0ubuntu0.10.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3-1d","version":"3.15.3-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.10.04.1"}],"quantal":[{"name":"nss","version":"3.15.3-0ubuntu0.12.10.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"3.15.3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.12.10.1"}],"raring":[{"name":"nss","version":"2:3.15.3-0ubuntu0.13.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.15.3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.15.3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-1741","CVE-2013-5605","CVE-2013-5606"]}]},{"id":"CVE-2013-5605","published":"2013-11-14T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before\n3.15.3 allows remote attackers to cause a denial of service or possibly\nhave unspecified other impact via invalid handshake packets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2030-1","http://www.mozilla.org/security/announce/2013/mfsa2013-103.html","https://ubuntu.com/security/notices/USN-2032-1","https://ubuntu.com/security/notices/USN-2031-1","https://www.cve.org/CVERecord?id=CVE-2013-5605"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=934016 (private)"],"patches":{"nss":[],"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0.1+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0.1+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0.1+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0.1+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0.1","component":null,"pocket":"security"}]},{"name":"nss","source":"https://ubuntu.com/security/cve?package=nss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nss","debian":"https://tracker.debian.org/pkg/nss","statuses":[{"release_codename":"lucid","status":"released","description":"3.15.3-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.15.3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.15.3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2:3.15.3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2:3.15.3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15.3","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.1+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.1+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.1+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.1+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2031-1","USN-2030-1","USN-2032-1"],"notices":[{"id":"USN-2031-1","title":"Firefox vulnerabilities","summary":"Several security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1251576"],"published":"2013-11-20T15:53:17.314212","description":"Multiple security issues were discovered in Firefox. If a user were tricked\ninto opening a specially crafted page, an attacker could possibly exploit\nthese to cause a denial of service via application crash, potentially\nexecute arbitrary code, or lead to information disclosure. (CVE-2013-1741,\nCVE-2013-2566, CVE-2013-5605, CVE-2013-5607)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1741","CVE-2013-2566","CVE-2013-5605","CVE-2013-5607"]},{"id":"USN-2030-1","title":"NSS vulnerabilities","summary":"Several security issues were fixed in NSS.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use NSS, such as Evolution and Chromium, to make all the necessary\nchanges.\n","references":[],"published":"2013-11-18T20:12:06.225636","description":"Multiple security issues were discovered in NSS. If a user were tricked\ninto connecting to a malicious server, an attacker could possibly exploit\nthese to cause a denial of service via application crash, potentially\nexecute arbitrary code, or lead to information disclosure.\n\nThis update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04\nLTS, Ubuntu 12.10, and Ubuntu 13.04.\n","is_hidden":false,"release_packages":{"precise":[{"name":"nss","version":"3.15.3-0ubuntu0.12.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"3.15.3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.12.04.1"}],"saucy":[{"name":"nss","version":"2:3.15.3-0ubuntu0.13.10.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.15.3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.15.3-0ubuntu0.13.10.1"}],"lucid":[{"name":"nss","version":"3.15.3-0ubuntu0.10.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3-1d","version":"3.15.3-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.10.04.1"}],"quantal":[{"name":"nss","version":"3.15.3-0ubuntu0.12.10.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"3.15.3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.12.10.1"}],"raring":[{"name":"nss","version":"2:3.15.3-0ubuntu0.13.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.15.3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.15.3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-1741","CVE-2013-5605","CVE-2013-5606"]},{"id":"USN-2032-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1253027"],"published":"2013-11-21T13:26:15.313994","description":"Multiple security issues were discovered in Thunderbird. If a user were\ntricked into connecting to a malicious server, an attacker could possibly\nexploit these to cause a denial of service via application crash,\npotentially execute arbitrary code, or lead to information disclosure.\n(CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1741","CVE-2013-2566","CVE-2013-5605","CVE-2013-5607"]}]},{"id":"CVE-2013-1741","published":"2013-11-14T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in Mozilla Network Security Services (NSS) 3.15 before\n3.15.3 allows remote attackers to cause a denial of service or possibly\nhave unspecified other impact via a large size value.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.3_release_notes","https://ubuntu.com/security/notices/USN-2030-1","http://www.mozilla.org/security/announce/2013/mfsa2013-103.html","https://ubuntu.com/security/notices/USN-2032-1","https://ubuntu.com/security/notices/USN-2031-1","https://www.cve.org/CVERecord?id=CVE-2013-1741"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=925100 (private)"],"patches":{"nss":[],"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0.1+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0.1+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0.1+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0.1+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0.1","component":null,"pocket":"security"}]},{"name":"nss","source":"https://ubuntu.com/security/cve?package=nss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nss","debian":"https://tracker.debian.org/pkg/nss","statuses":[{"release_codename":"lucid","status":"released","description":"3.15.3-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.15.3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.15.3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2:3.15.3-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2:3.15.3-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.15.3","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1:24.1.1+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1:24.1.1+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1:24.1.1+build1-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1:24.1.1+build1-0ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"24.1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2031-1","USN-2030-1","USN-2032-1"],"notices":[{"id":"USN-2031-1","title":"Firefox vulnerabilities","summary":"Several security issues were fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1251576"],"published":"2013-11-20T15:53:17.314212","description":"Multiple security issues were discovered in Firefox. If a user were tricked\ninto opening a specially crafted page, an attacker could possibly exploit\nthese to cause a denial of service via application crash, potentially\nexecute arbitrary code, or lead to information disclosure. (CVE-2013-1741,\nCVE-2013-2566, CVE-2013-5605, CVE-2013-5607)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"25.0.1+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/25.0.1+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1741","CVE-2013-2566","CVE-2013-5605","CVE-2013-5607"]},{"id":"USN-2030-1","title":"NSS vulnerabilities","summary":"Several security issues were fixed in NSS.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use NSS, such as Evolution and Chromium, to make all the necessary\nchanges.\n","references":[],"published":"2013-11-18T20:12:06.225636","description":"Multiple security issues were discovered in NSS. If a user were tricked\ninto connecting to a malicious server, an attacker could possibly exploit\nthese to cause a denial of service via application crash, potentially\nexecute arbitrary code, or lead to information disclosure.\n\nThis update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04\nLTS, Ubuntu 12.10, and Ubuntu 13.04.\n","is_hidden":false,"release_packages":{"precise":[{"name":"nss","version":"3.15.3-0ubuntu0.12.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"3.15.3-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.12.04.1"}],"saucy":[{"name":"nss","version":"2:3.15.3-0ubuntu0.13.10.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.15.3-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.15.3-0ubuntu0.13.10.1"}],"lucid":[{"name":"nss","version":"3.15.3-0ubuntu0.10.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3-1d","version":"3.15.3-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.10.04.1"}],"quantal":[{"name":"nss","version":"3.15.3-0ubuntu0.12.10.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"3.15.3-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/3.15.3-0ubuntu0.12.10.1"}],"raring":[{"name":"nss","version":"2:3.15.3-0ubuntu0.13.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.15.3-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.15.3-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1739","CVE-2013-1741","CVE-2013-5605","CVE-2013-5606"]},{"id":"USN-2032-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1253027"],"published":"2013-11-21T13:26:15.313994","description":"Multiple security issues were discovered in Thunderbird. If a user were\ntricked into connecting to a malicious server, an attacker could possibly\nexploit these to cause a denial of service via application crash,\npotentially execute arbitrary code, or lead to information disclosure.\n(CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.12.04.1"}],"saucy":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.13.10.1"}],"quantal":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.12.10.1"}],"raring":[{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"1:24.1.1+build1-0ubuntu0.13.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/1:24.1.1+build1-0ubuntu0.13.04.1"}]},"type":"USN","cves_ids":["CVE-2013-1741","CVE-2013-2566","CVE-2013-5605","CVE-2013-5607"]}]},{"id":"CVE-2013-6780","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in uploader.swf in the Uploader\ncomponent in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to\ninject arbitrary web script or HTML via the allowedDomain parameter.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"maas uses an embedded copy of yui 3.4.1 in 12.04 and portions of\nyui3 in 12.10 and higher"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://yuilibrary.com/support/20131111-vulnerability/","https://www.cve.org/CVERecord?id=CVE-2013-6780"],"bugs":[""],"patches":{"yui3":[],"yui":[],"maas":[]},"tags":{},"packages":[{"name":"maas","source":"https://ubuntu.com/security/cve?package=maas","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=maas","debian":"https://tracker.debian.org/pkg/maas","statuses":[{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"yui","source":"https://ubuntu.com/security/cve?package=yui","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=yui","debian":"https://tracker.debian.org/pkg/yui","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"yui3","source":"https://ubuntu.com/security/cve?package=yui3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=yui3","debian":"https://tracker.debian.org/pkg/yui3","statuses":[{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6628","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnet/socket/ssl_client_socket_nss.cc in the TLS implementation in Google\nChrome before 31.0.1650.48 does not ensure that a server's X.509\ncertificate is the same during renegotiation as it was before\nrenegotiation, which might allow remote web servers to interfere with trust\nrelationships by renegotiating a session.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=229611&view=revision","https://code.google.com/p/chromium/issues/detail?id=306959","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6628"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6627","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnet/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does\nnot properly process HTTP Informational (aka 1xx) status codes, which\nallows remote web servers to cause a denial of service (out-of-bounds read)\nvia a crafted response.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=226539&view=revision","https://code.google.com/p/chromium/issues/detail?id=299892","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6627"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6626","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe WebContentsImpl::AttachInterstitialPage function in\ncontent/browser/web_contents/web_contents_impl.cc in Google Chrome before\n31.0.1650.48 does not cancel JavaScript dialogs upon generating an\ninterstitial warning, which allows remote attackers to spoof the address\nbar via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/chrome?revision=225026&view=revision","https://code.google.com/p/chromium/issues/detail?id=295695","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6626"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6625","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in core/dom/ContainerNode.cpp in Blink, as\nused in Google Chrome before 31.0.1650.48, allows remote attackers to cause\na denial of service or possibly have unspecified other impact by leveraging\nimproper handling of DOM range objects in circumstances that require child\nnode removal after a (1) mutation or (2) blur event.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=160037&view=revision","https://code.google.com/p/chromium/issues/detail?id=295010","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6625"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6624","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 31.0.1650.48 allows\nremote attackers to cause a denial of service or possibly have unspecified\nother impact via vectors involving the string values of id attributes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=290566","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6624"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6623","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SVG implementation in Blink, as used in Google Chrome before\n31.0.1650.48, allows remote attackers to cause a denial of service\n(out-of-bounds read) by leveraging the use of tree order, rather than\ntransitive dependency order, for layout.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=158480&view=revision","https://code.google.com/p/chromium/issues/detail?id=282925","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6623"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6622","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument\nfunction in core/html/HTMLMediaElement.cpp in Blink, as used in Google\nChrome before 31.0.1650.48, allows remote attackers to cause a denial of\nservice or possibly have unspecified other impact via vectors involving the\nmovement of a media element between documents.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://src.chromium.org/viewvc/blink?revision=159031&view=revision","https://code.google.com/p/chromium/issues/detail?id=272786","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6622"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6621","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 31.0.1650.48 allows\nremote attackers to cause a denial of service or possibly have unspecified\nother impact via vectors related to the x-webkit-speech attribute in a text\nINPUT element.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=268565","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-6621"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6357","published":"2013-11-13T15:55:00","updated_at":"2025-08-04T19:24:24.192941+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in the Manager application\nin Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the\nauthentication of administrators for requests that manipulate application\ndeployment via the POST method, as demonstrated by a\n/manager/html/undeploy?path= URI. NOTE: the vendor disputes the\nsignificance of this report, stating that \"the Apache Tomcat Security team\nhas not accepted any reports of CSRF attacks against the Manager\napplication ... as they require a reckless system administrator.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"DISPUTED by vendor; apparently not in tomcat6 or tomcat7"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.webapp-security.com/wp-content/uploads/2013/11/Apache-Tomcat-5.5.25-CSRF-Vulnerabilities.txt","https://www.cve.org/CVERecord?id=CVE-2013-6357"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[]},"tags":{},"packages":[{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4476","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSamba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is\nprovided over SSL, uses world-readable permissions for a private key, which\nallows local users to obtain sensitive information by reading the key file,\nas demonstrated by access to the local filesystem on an AD domain\ncontroller.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Doesn't apply to 3.x"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.samba.org/samba/security/CVE-2013-4476","http://www.samba.org/samba/history/samba-4.1.1.html","http://www.samba.org/samba/history/samba-4.0.11.html","https://www.cve.org/CVERecord?id=CVE-2013-4476"],"bugs":[""],"patches":{"samba4":["upstream: http://www.samba.org/samba/ftp/patches/security/samba-4.1.0-CVE-2013-4475-CVE-2013-4476.patch","upstream: http://www.samba.org/samba/ftp/patches/security/samba-4.0.10-CVE-2013-4475-CVE-2013-4476.patch"],"samba":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"samba4","source":"https://ubuntu.com/security/cve?package=samba4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba4","debian":"https://tracker.debian.org/pkg/samba4","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.11, 4.1.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2931","published":"2013-11-13T15:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48\nallow attackers to execute arbitrary code or possibly have other impact via\nunknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://code.google.com/p/chromium/issues/detail?id=315823","https://code.google.com/p/chromium/issues/detail?id=314225","https://code.google.com/p/chromium/issues/detail?id=306255","https://code.google.com/p/chromium/issues/detail?id=304226","https://code.google.com/p/chromium/issues/detail?id=303232","https://code.google.com/p/chromium/issues/detail?id=302810","https://code.google.com/p/chromium/issues/detail?id=299993","https://code.google.com/p/chromium/issues/detail?id=299835","https://code.google.com/p/chromium/issues/detail?id=297556","https://code.google.com/p/chromium/issues/detail?id=296804","https://code.google.com/p/chromium/issues/detail?id=296276","https://code.google.com/p/chromium/issues/detail?id=286368","https://code.google.com/p/chromium/issues/detail?id=285578","https://code.google.com/p/chromium/issues/detail?id=282738","https://code.google.com/p/chromium/issues/detail?id=271235","https://code.google.com/p/chromium/issues/detail?id=264574","https://code.google.com/p/chromium/issues/detail?id=263255","https://code.google.com/p/chromium/issues/detail?id=258723","http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2013-2931"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"31.0.1650.63-0ubuntu0.12.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"31.0.1650.63-0ubuntu0.12.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"31.0.1650.63-0ubuntu0.13.04.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"31.0.1650.63-0ubuntu0.13.10.1~20131204.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"31.0.1650.48","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5330","published":"2013-11-13T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before\n11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux,\nAdobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR\nSDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code\nor cause a denial of service (memory corruption) via unspecified vectors, a\ndifferent vulnerability than CVE-2013-5329.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb13-26.html","https://www.cve.org/CVERecord?id=CVE-2013-5330"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.327-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.327-0quantal1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"11.2.202.327-0raring1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.327-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.327","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.327ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.327ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"11.2.202.327ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.327ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.327","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-5329","published":"2013-11-13T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nAdobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before\n11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux,\nAdobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR\nSDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code\nor cause a denial of service (memory corruption) via unspecified vectors, a\ndifferent vulnerability than CVE-2013-5330.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.adobe.com/support/security/bulletins/apsb13-26.html","https://www.cve.org/CVERecord?id=CVE-2013-5329"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.327-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.327-0quantal1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"11.2.202.327-0raring1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.327-0saucy1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.327","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.327ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.327ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"11.2.202.327ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"11.2.202.327ubuntu0.13.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.327","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4475","published":"2013-11-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSamba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x\nbefore 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled,\nallows remote attackers to bypass intended file restrictions by leveraging\nACL differences between a file and an associated alternate data stream\n(ADS).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"per Upstream, Samba 3.2.0 and higher\nnot a default config"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://lists.samba.org/archive/samba-technical/2013-October/095725.html","http://www.samba.org/samba/security/CVE-2013-4475","https://ubuntu.com/security/notices/USN-2054-1","https://www.cve.org/CVERecord?id=CVE-2013-4475"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1024542","https://bugzilla.samba.org/show_bug.cgi?id=10235 (private)","https://bugzilla.samba.org/show_bug.cgi?id=10229"],"patches":{"samba4":[],"samba":["upstream: http://git.samba.org/?p=samba.git;a=commit;h=14d48130870579541c07f5a0f64638e635ddce95"]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"lucid","status":"released","description":"2:3.4.7~dfsg-1ubuntu3.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:3.6.3-2ubuntu2.9","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2:3.6.6-3ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2:3.6.9-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2:3.6.18-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:4.0.13+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.20","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"2:4.0.13+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"2:4.0.13+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2:4.0.13+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:4.0.13+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:4.0.13+dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:4.0.13+dfsg-1ubuntu1","component":null,"pocket":"security"}]},{"name":"samba4","source":"https://ubuntu.com/security/cve?package=samba4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba4","debian":"https://tracker.debian.org/pkg/samba4","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.1.1,4.0.11","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2054-1"],"notices":[{"id":"USN-2054-1","title":"Samba vulnerabilities","summary":"Several security issues were fixed in Samba.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-12-11T13:13:58.603292","description":"It was discovered that Winbind incorrectly handled invalid group names with\nthe require_membership_of parameter. If an administrator used an invalid\ngroup name by mistake, access was granted instead of having the login fail.\n(CVE-2012-6150)\n\nStefan Metzmacher and Michael Adam discovered that Samba incorrectly\nhandled DCE-RPC fragment length fields. A remote attacker could use this\nissue to cause Samba to crash, resulting in a denial of service, or\npossibly execute arbitrary code as the root user. (CVE-2013-4408)\n\nHemanth Thummala discovered that Samba incorrectly handled file\npermissions when vfs_streams_depot or vfs_streams_xattr were enabled. A\nremote attacker could use this issue to bypass intended restrictions.\n(CVE-2013-4475)\n","is_hidden":false,"release_packages":{"precise":[{"name":"samba","version":"2:3.6.3-2ubuntu2.9","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:3.6.3-2ubuntu2.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.3-2ubuntu2.9"},{"name":"libpam-winbind","version":"2:3.6.3-2ubuntu2.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.3-2ubuntu2.9"}],"saucy":[{"name":"samba","version":"2:3.6.18-1ubuntu3.1","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:3.6.18-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.18-1ubuntu3.1"},{"name":"libpam-winbind","version":"2:3.6.18-1ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.18-1ubuntu3.1"}],"lucid":[{"name":"samba","version":"2:3.4.7~dfsg-1ubuntu3.13","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"winbind","version":"2:3.4.7~dfsg-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.4.7~dfsg-1ubuntu3.13"},{"name":"samba","version":"2:3.4.7~dfsg-1ubuntu3.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.4.7~dfsg-1ubuntu3.13"}],"quantal":[{"name":"samba","version":"2:3.6.6-3ubuntu5.3","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:3.6.6-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.6-3ubuntu5.3"},{"name":"libpam-winbind","version":"2:3.6.6-3ubuntu5.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.6-3ubuntu5.3"}],"raring":[{"name":"samba","version":"2:3.6.9-1ubuntu1.2","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:3.6.9-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.9-1ubuntu1.2"},{"name":"libpam-winbind","version":"2:3.6.9-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.9-1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2012-6150","CVE-2013-4408","CVE-2013-4475"]}]},{"id":"CVE-2013-4512","published":"2013-11-12T14:35:00","updated_at":"2026-07-04T07:36:12.966678+00:00","description":"\nBuffer overflow in the exitcode_proc_write function in\narch/um/kernel/exitcode.c in the Linux kernel before 3.12 allows local\nusers to cause a denial of service or possibly have unspecified other\nimpact by leveraging root privileges for a write operation.","ubuntu_description":"\nA buffer overflow was discovered in exit function for the Linux kernel\nwhen used for User Mode Linux. A local user could exploit this flaw to\ncause a denial of service or possibly gain administrative privileges.","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=201f99f170df14ba52ea4c52847779042b7a623b","https://www.cve.org/CVERecord?id=CVE-2013-4512"],"bugs":["https://launchpad.net/bugs/1249271"],"patches":{"linux":["break-fix: - 201f99f170df14ba52ea4c52847779042b7a623b"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"]},"packages":[{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [CVE in User Mode Linux]","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [CVE in User Mode Linux]","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.12.0-2.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-6763","published":"2013-11-12T00:00:00","updated_at":"2026-07-04T07:37:19.799016+00:00","description":"\nThe uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel\nbefore 3.12 does not validate the size of a memory block, which allows\nlocal users to cause a denial of service (memory corruption) or possibly\ngain privileges via crafted mmap operations, a different vulnerability than\nCVE-2013-4511.","ubuntu_description":"\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges.","notes":[{"author":"seth-arnold","note":"Marked 'low' because uio_mmap_physical()'s only caller does length\nchecking before the call, see the 12 November 2013 oss-security mail from\nPetr Matousek."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.12.bz2","https://github.com/torvalds/linux/commit/7314e613d5ff9f0934f7a0f74ed7973b903315d1","http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7314e613d5ff9f0934f7a0f74ed7973b903315d1","http://www.openwall.com/lists/oss-security/2013/11/04/22","http://www.openwall.com/lists/oss-security/2013/11/12/1","https://ubuntu.com/security/notices/USN-2064-1","https://ubuntu.com/security/notices/USN-2065-1","https://ubuntu.com/security/notices/USN-2066-1","https://ubuntu.com/security/notices/USN-2067-1","https://ubuntu.com/security/notices/USN-2068-1","https://ubuntu.com/security/notices/USN-2069-1","https://ubuntu.com/security/notices/USN-2070-1","https://ubuntu.com/security/notices/USN-2071-1","https://ubuntu.com/security/notices/USN-2072-1","https://ubuntu.com/security/notices/USN-2073-1","https://ubuntu.com/security/notices/USN-2074-1","https://ubuntu.com/security/notices/USN-2075-1","https://ubuntu.com/security/notices/USN-2076-1","https://www.cve.org/CVERecord?id=CVE-2013-6763"],"bugs":["https://launchpad.net/bugs/1252426"],"patches":{"linux":["break-fix: - 7314e613d5ff9f0934f7a0f74ed7973b903315d1"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"lucid","status":"released","description":"2.6.32-55.117","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-58.88","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-45.68","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"3.8.0-35.50","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"3.11.0-15.23","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.12.0-2.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1629.41","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-1626.35","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"lucid","status":"released","description":"2.6.32-360.73","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.5.0-45.68~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.8.0-35.50~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.11.0-15.23~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1442.61","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-237.53","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"3.5.0-237.53","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"3.5.0-237.53","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2071-1","USN-2075-1","USN-2067-1","USN-2074-1","USN-2069-1","USN-2076-1","USN-2073-1","USN-2068-1","USN-2066-1","USN-2064-1","USN-2070-1","USN-2072-1","USN-2065-1"],"notices":[{"id":"USN-2071-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:58:15.740705","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux","version":"3.5.0-45.68","description":"Linux kernel","is_source":true},{"name":"linux-image-3.5.0-45-omap","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-generic","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-highbank","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-powerpc-smp","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-powerpc64-smp","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2075-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T11:07:55.631603","description":"Vasily Kulikov reported a flaw in the Linux kernel's implementation of\nptrace. An unprivileged local user could exploit this flaw to obtain\nsensitive information from kernel memory. (CVE-2013-2929)\n\nDave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for the SystemBase Multi-2/PCI serial card. An unprivileged user\ncould obtain sensitive information from kernel memory. (CVE-2013-4516)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec\nAACRAID scsi raid devices in the Linux kernel. A local user could use this\nflaw to cause a denial of service or possibly other unspecified impact.\n(CVE-2013-6380)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nA race condition flaw was discovered in the Linux kernel's ipc shared\nmemory implimentation. A local user could exploit this flaw to cause a\ndenial of service (system crash) or possibly have unspecied other impacts.\n(CVE-2013-7026)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"linux","version":"3.11.0-15.23","description":"Linux kernel","is_source":true},{"name":"linux-image-3.11.0-15-generic-lpae","version":"3.11.0-15.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.11.0-15.23"},{"name":"linux-image-3.11.0-15-generic","version":"3.11.0-15.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.11.0-15.23"}]},"type":"USN","cves_ids":["CVE-2013-2929","CVE-2013-2930","CVE-2013-4345","CVE-2013-4348","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-4516","CVE-2013-6378","CVE-2013-6380","CVE-2013-6383","CVE-2013-6763","CVE-2013-7026"]},{"id":"USN-2067-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:44:52.255395","description":"\nA flaw was discovered in the Linux kernel's dm snapshot facility. A remote\nauthenticated user could exploit this flaw to obtain sensitive information\nor modify/corrupt data. (CVE-2013-4299)\n\nHannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw in the handling of memory regions of the kernel virtual machine\n(KVM) subsystem was discovered. A local user with the ability to assign a\ndevice could exploit this flaw to cause a denial of service (memory\nconsumption). (CVE-2013-4592)\n\nCatalin Marinas reported a flaw in the get_user and put_user API functions\nin the Linux kernel on ARM platforms. An unprivileged local user could\nexploit this flaw to gain administrator privileges. (CVE-2013-6282)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n\nAn information leak was discovered in the Linux kernel's SIOCWANDEV ioctl\ncall. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to obtain potentially sensitive information from kernel memory.\n(CVE-2014-1444)\n\nAn information leak was discovered in the wanxl ioctl function the Linux\nkernel. A local user could exploit this flaw to obtain potentially\nsensitive information from kernel memory. (CVE-2014-1445)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-ti-omap4","version":"3.2.0-1442.61","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.2.0-1442-omap4","version":"3.2.0-1442.61","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1442.61"}]},"type":"USN","cves_ids":["CVE-2013-4299","CVE-2013-4470","CVE-2013-4511","CVE-2013-4514","CVE-2013-4515","CVE-2013-4592","CVE-2013-6282","CVE-2013-6378","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027","CVE-2014-1444","CVE-2014-1445"]},{"id":"USN-2074-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T11:11:02.159414","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"raring":[{"name":"linux-ti-omap4","version":"3.5.0-237.53","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-237-omap4","version":"3.5.0-237.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2069-1","title":"Linux kernel (Raring HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:52:58.186015","description":"\nHannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for the SystemBase Multi-2/PCI serial card. An unprivileged user\ncould obtain sensitive information from kernel memory. (CVE-2013-4516)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n\nAn information leak was discovered in the Linux kernel's SIOCWANDEV ioctl\ncall. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to obtain potentially sensitive information from kernel memory.\n(CVE-2014-1444)\n\nAn information leak was discovered in the wanxl ioctl function the Linux\nkernel. A local user could exploit this flaw to obtain potentially\nsensitive information from kernel memory. (CVE-2014-1445)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-raring","version":"3.8.0-35.50~precise1","description":"Linux hardware enablement kernel from Raring","is_source":true},{"name":"linux-image-3.8.0-35-generic","version":"3.8.0-35.50~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-raring","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-raring/3.8.0-35.50~precise1"}]},"type":"USN","cves_ids":["CVE-2013-4470","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-4516","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027","CVE-2014-1444","CVE-2014-1445"]},{"id":"USN-2076-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T11:12:05.627099","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"linux-ti-omap4","version":"3.5.0-237.53","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-237-omap4","version":"3.5.0-237.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2073-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T11:01:44.350184","description":"Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for the SystemBase Multi-2/PCI serial card. An unprivileged user\ncould obtain sensitive information from kernel memory. (CVE-2013-4516)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"raring":[{"name":"linux","version":"3.8.0-35.50","description":"Linux kernel","is_source":true},{"name":"linux-image-3.8.0-35-generic","version":"3.8.0-35.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.8.0-35.50"}]},"type":"USN","cves_ids":["CVE-2013-4470","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-4516","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2068-1","title":"Linux kernel (Quantal HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:51:28.340288","description":"\nDave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-quantal","version":"3.5.0-45.68~precise1","description":"Linux hardware enablement kernel from Quantal","is_source":true},{"name":"linux-image-3.5.0-45-generic","version":"3.5.0-45.68~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-45.68~precise1"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4348","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2066-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:39:01.280824","description":"\nA flaw was discovered in the Linux kernel's dm snapshot facility. A remote\nauthenticated user could exploit this flaw to obtain sensitive information\nor modify/corrupt data. (CVE-2013-4299)\n\nHannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw in the handling of memory regions of the kernel virtual machine\n(KVM) subsystem was discovered. A local user with the ability to assign a\ndevice could exploit this flaw to cause a denial of service (memory\nconsumption). (CVE-2013-4592)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n\nAn information leak was discovered in the Linux kernel's SIOCWANDEV ioctl\ncall. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to obtain potentially sensitive information from kernel memory.\n(CVE-2014-1444)\n\nAn information leak was discovered in the wanxl ioctl function the Linux\nkernel. A local user could exploit this flaw to obtain potentially\nsensitive information from kernel memory. (CVE-2014-1445)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux","version":"3.2.0-58.88","description":"Linux kernel","is_source":true},{"name":"linux-image-3.2.0-58-omap","version":"3.2.0-58.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88"},{"name":"linux-image-3.2.0-58-powerpc-smp","version":"3.2.0-58.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88"},{"name":"linux-image-3.2.0-58-virtual","version":"3.2.0-58.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88"},{"name":"linux-image-3.2.0-58-powerpc64-smp","version":"3.2.0-58.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88"},{"name":"linux-image-3.2.0-58-generic-pae","version":"3.2.0-58.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88"},{"name":"linux-image-3.2.0-58-highbank","version":"3.2.0-58.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88"},{"name":"linux-image-3.2.0-58-generic","version":"3.2.0-58.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88"}]},"type":"USN","cves_ids":["CVE-2013-4299","CVE-2013-4470","CVE-2013-4511","CVE-2013-4514","CVE-2013-4515","CVE-2013-4592","CVE-2013-6378","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027","CVE-2014-1444","CVE-2014-1445"]},{"id":"USN-2064-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:13:29.614795","description":"Stephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nA flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)\nsupport. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to gain additional administrative privileges. (CVE-2013-4588)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-55.117","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-55-lpia","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-powerpc64-smp","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-generic-pae","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-versatile","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-generic","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-virtual","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-ia64","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-powerpc-smp","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-386","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-powerpc","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-server","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-sparc64","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-sparc64-smp","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-preempt","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"}]},"type":"USN","cves_ids":["CVE-2013-4345","CVE-2013-4588","CVE-2013-6378","CVE-2013-6763"]},{"id":"USN-2070-1","title":"Linux kernel (Saucy HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:55:40.391340","description":"Vasily Kulikov reported a flaw in the Linux kernel's implementation of\nptrace. An unprivileged local user could exploit this flaw to obtain\nsensitive information from kernel memory. (CVE-2013-2929)\n\nDave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for the SystemBase Multi-2/PCI serial card. An unprivileged user\ncould obtain sensitive information from kernel memory. (CVE-2013-4516)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec\nAACRAID scsi raid devices in the Linux kernel. A local user could use this\nflaw to cause a denial of service or possibly other unspecified impact.\n(CVE-2013-6380)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nA race condition flaw was discovered in the Linux kernel's ipc shared\nmemory implimentation. A local user could exploit this flaw to cause a\ndenial of service (system crash) or possibly have unspecied other impacts.\n(CVE-2013-7026)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-saucy","version":"3.11.0-15.23~precise1","description":"Linux hardware enablement kernel from Saucy","is_source":true},{"name":"linux-image-3.11.0-15-generic-lpae","version":"3.11.0-15.23~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-15.23~precise1"},{"name":"linux-image-3.11.0-15-generic","version":"3.11.0-15.23~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-15.23~precise1"}]},"type":"USN","cves_ids":["CVE-2013-2929","CVE-2013-2930","CVE-2013-4345","CVE-2013-4348","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-4516","CVE-2013-6378","CVE-2013-6380","CVE-2013-6383","CVE-2013-6763","CVE-2013-7026"]},{"id":"USN-2072-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:59:49.262411","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux-ti-omap4","version":"3.5.0-237.53","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-237-omap4","version":"3.5.0-237.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2065-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:29:27.276183","description":"Stephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nA flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)\nsupport. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to gain additional administrative privileges. (CVE-2013-4588)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-360.73","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-360-ec2","version":"2.6.32-360.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-360.73"}]},"type":"USN","cves_ids":["CVE-2013-4345","CVE-2013-4588","CVE-2013-6378","CVE-2013-6763"]}]}],"offset":66660,"limit":20,"total_results":79316}