{"cves":[{"id":"CVE-2013-4342","published":"2013-10-10T00:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nxinetd does not enforce the user and group configuration directives for\nTCPMUX services, which causes these services to be run as root and makes it\neasier for remote attackers to gain privileges by leveraging another\nvulnerability in a service.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-4342"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=324678"],"patches":{"xinetd":["vendor: https://rhn.redhat.com/errata/RHSA-2013-1409.html","other: https://github.com/xinetd-org/xinetd/pull/10/files"]},"tags":{},"packages":[{"name":"xinetd","source":"https://ubuntu.com/security/cve?package=xinetd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xinetd","debian":"https://tracker.debian.org/pkg/xinetd","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:2.3.15-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.3.15-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:2.3.15-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.3.15-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:2.3.15-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:2.3.15-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1:2.3.15-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:2.3.15-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:2.3.15-6","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4271","published":"2013-10-10T00:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of the ObjectRepresentation class in Restlet\nbefore 2.1.4 deserializes objects from untrusted sources, which allows\nremote attackers to execute arbitrary Java code via a serialized object, a\ndifferent vulnerability than CVE-2013-4221.","ubuntu_description":"","notes":[{"author":"pfsmorigo","note":"https://github.com/restlet/restlet-framework-java/issues/826"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2013-1410.html","https://www.cve.org/CVERecord?id=CVE-2013-4271"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=596472"],"patches":{"restlet":[]},"tags":{},"packages":[{"name":"restlet","source":"https://ubuntu.com/security/cve?package=restlet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=restlet","debian":"https://tracker.debian.org/pkg/restlet","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4221","published":"2013-10-10T00:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of the ObjectRepresentation class in Restlet\nbefore 2.1.4 deserializes objects from untrusted sources using the Java\nXMLDecoder, which allows remote attackers to execute arbitrary Java code\nvia crafted XML.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.diniscruz.com/2013/08/using-xmldecoder-to-execute-server-side.html","https://github.com/o2platform/DefCon_RESTing","https://www.cve.org/CVERecord?id=CVE-2013-4221"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=596472"],"patches":{"restlet":[]},"tags":{},"packages":[{"name":"restlet","source":"https://ubuntu.com/security/cve?package=restlet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=restlet","debian":"https://tracker.debian.org/pkg/restlet","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2138","published":"2013-10-10T00:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do\nnot properly remove query parameters and fragments, which allows remote\nattackers to have an unspecified impact via a replay attack.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"our versions of gallery and gallery2 do not have the swf files,\nand other packages with uploadify don't appear to have the same issue\non first inspection"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/06/04","https://www.cve.org/CVERecord?id=CVE-2013-2138"],"bugs":[""],"patches":{"gallery":[],"gallery2":[]},"tags":{},"packages":[{"name":"gallery","source":"https://ubuntu.com/security/cve?package=gallery","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gallery","debian":"https://tracker.debian.org/pkg/gallery","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"gallery2","source":"https://ubuntu.com/security/cve?package=gallery2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gallery2","debian":"https://tracker.debian.org/pkg/gallery2","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4396","published":"2013-10-10T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the doImageText function in dix/dixfonts.c\nin the xorg-server module before 1.14.4 in X.Org X11 allows remote\nauthenticated users to cause a denial of service (daemon crash) or possibly\nexecute arbitrary code via a crafted ImageText request that triggers\nmemory-allocation failure.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/10/08/6","https://ubuntu.com/security/notices/USN-1990-1","https://www.cve.org/CVERecord?id=CVE-2013-4396"],"bugs":[""],"patches":{"xorg-server":["upstream: 7bddc2ba16a2a15773c2ea8947059afa27727764"],"xorg-server-lts-quantal":[],"xorg-server-lts-raring":[]},"tags":{},"packages":[{"name":"xorg-server","source":"https://ubuntu.com/security/cve?package=xorg-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server","debian":"https://tracker.debian.org/pkg/xorg-server","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.11.4-0ubuntu10.14","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2:1.13.0-0ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2:1.13.3-0ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:1.14.3-4","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-quantal","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-quantal","debian":"https://tracker.debian.org/pkg/xorg-server-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.13.0-0ubuntu6.1~precise4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xorg-server-lts-raring","source":"https://ubuntu.com/security/cve?package=xorg-server-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xorg-server-lts-raring","debian":"https://tracker.debian.org/pkg/xorg-server-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2:1.13.3-0ubuntu6~precise3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1990-1"],"notices":[{"id":"USN-1990-1","title":"X.Org X server vulnerabilities","summary":"The X.Org X server could be made to crash or run programs as an\nadministrator if it received specially crafted input.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-10-17T17:22:36.351496","description":"Pedro Ribeiro discovered that the X.Org X server incorrectly handled\nmemory operations when handling ImageText requests. An attacker could use\nthis issue to cause X.Org to crash, or to possibly execute arbitrary code.\n(CVE-2013-4396)\n\nIt was discovered that non-root X.Org X servers such as Xephyr incorrectly\nused cached xkb files. A local attacker could use this flaw to cause a xkb\ncache file to be loaded by another user, resulting in a denial of service.\n(CVE-2013-1056)\n","is_hidden":false,"release_packages":{"precise":[{"name":"xorg-server-lts-quantal","version":"2:1.13.0-0ubuntu6.1~precise4","description":"X.Org X11 server","is_source":true},{"name":"xorg-server","version":"2:1.11.4-0ubuntu10.14","description":"X.Org X11 server","is_source":true},{"name":"xorg-server-lts-raring","version":"2:1.13.3-0ubuntu6~precise3","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core-lts-quantal","version":"2:1.13.0-0ubuntu6.1~precise4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-quantal","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-quantal/2:1.13.0-0ubuntu6.1~precise4"},{"name":"xserver-xorg-core","version":"2:1.11.4-0ubuntu10.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.11.4-0ubuntu10.14"},{"name":"xserver-xorg-core-lts-raring","version":"2:1.13.3-0ubuntu6~precise3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-raring","version_link":"https://launchpad.net/ubuntu/+source/xorg-server-lts-raring/2:1.13.3-0ubuntu6~precise3"}],"quantal":[{"name":"xorg-server","version":"2:1.13.0-0ubuntu6.4","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.13.0-0ubuntu6.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.13.0-0ubuntu6.4"}],"raring":[{"name":"xorg-server","version":"2:1.13.3-0ubuntu6.2","description":"X.Org X11 server","is_source":true},{"name":"xserver-xorg-core","version":"2:1.13.3-0ubuntu6.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xorg-server","version_link":"https://launchpad.net/ubuntu/+source/xorg-server/2:1.13.3-0ubuntu6.2"}]},"type":"USN","cves_ids":["CVE-2013-1056","CVE-2013-4396"]}]},{"id":"CVE-2013-4387","published":"2013-10-10T00:00:00","updated_at":"2026-07-04T07:37:19.799016+00:00","description":"\nnet/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly\ndetermine the need for UDP Fragmentation Offload (UFO) processing of small\npackets after the UFO queueing of a large packet, which allows remote\nattackers to cause a denial of service (memory corruption and system crash)\nor possibly have unspecified other impact via network traffic that triggers\na large response packet.","ubuntu_description":"\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash).","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/09/28/1","https://ubuntu.com/security/notices/USN-2019-1","https://ubuntu.com/security/notices/USN-2021-1","https://ubuntu.com/security/notices/USN-2022-1","https://ubuntu.com/security/notices/USN-2024-1","https://ubuntu.com/security/notices/USN-2038-1","https://ubuntu.com/security/notices/USN-2039-1","https://ubuntu.com/security/notices/USN-2041-1","https://ubuntu.com/security/notices/USN-2045-1","https://ubuntu.com/security/notices/USN-2050-1","https://ubuntu.com/security/notices/USN-2049-1","https://ubuntu.com/security/notices/USN-2233-1","https://ubuntu.com/security/notices/USN-2234-1","https://www.cve.org/CVERecord?id=CVE-2013-4387"],"bugs":["https://launchpad.net/bugs/1235136"],"patches":{"linux":["break-fix: e89e9cf539a28df7d0eb1d0a545368e9920b34ac 2811ebac2521ceac84f2bdae402455baa6a7fb47"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-2.6":[],"linux-lts-saucy":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"lucid","status":"released","description":"2.6.32-61.124","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-57.87","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-43.66","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"3.8.0-34.49","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"3.11.0-13.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.12.0-1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"}]},{"name":"linux-2.6","source":"https://ubuntu.com/security/cve?package=linux-2.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-2.6","debian":"https://tracker.debian.org/pkg/linux-2.6","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1628.40","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-1624.33","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"lucid","status":"released","description":"2.6.32-365.79","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-4.20","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.5.0-43.66~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.8.0-34.49~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.11.0-13.20~precise2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1441.60","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-235.51","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"3.5.0-235.51","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"3.5.0-235.51","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.12~rc4","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-2019-1","USN-2038-1","USN-2041-1","USN-2234-1","USN-2021-1","USN-2045-1","USN-2022-1","USN-2039-1","USN-2050-1","USN-2233-1","USN-2024-1","USN-2049-1"],"notices":[{"id":"USN-2019-1","title":"Linux kernel (Quantal HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-11-08T21:47:18.215681","description":"An information leak was discovered in the handling of ICMPv6 Router\nAdvertisement (RA) messages in the Linux kernel's IPv6 network stack. A\nremote attacker could exploit this flaw to cause a denial of service\n(excessive retries and address-generation outage), and consequently obtain\nsensitive information. (CVE-2013-0343)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem of\nthe Linux kernel. A physically proximate attacker could exploit this flaw\nto execute arbitrary code or cause a denial of service (heap memory\ncorruption) via a specially crafted device that provides an invalid Report\nID. (CVE-2013-2888)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem\nwhen CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could\nleverage this flaw to cause a denial of service via a specially crafted\ndevice. (CVE-2013-2889)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically\nproximate attacker could cause a denial of service (heap out-of-bounds\nwrite) via a specially crafted device. (CVE-2013-2892)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,\nCONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially\nproximate attacker can leverage this flaw to cause a denial of service vias\na specially crafted device. (CVE-2013-2893)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A\nphysically proximate attacker could cause a denial of service (OOPS) or\nobtain sensitive information from kernel memory via a specially crafted\ndevice. (CVE-2013-2895)\n\nKees Cook discovered a vulnerability in the Linux Kernel's Human Interface\nDevice (HID) subsystem's support for N-Trig touch screens. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2896)\n\nKees Cook discovered yet another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A\nphysically proximate attacker could leverage this flaw to cause a denial of\nservice (OOPS) via a specially crafted device. (CVE-2013-2897)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2899)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-quantal","version":"3.5.0-43.66~precise1","description":"Linux hardware enablement kernel from Quantal","is_source":true},{"name":"linux-image-3.5.0-43-generic","version":"3.5.0-43.66~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-43.66~precise1"}]},"type":"USN","cves_ids":["CVE-2013-0343","CVE-2013-2888","CVE-2013-2889","CVE-2013-2892","CVE-2013-2893","CVE-2013-2895","CVE-2013-2896","CVE-2013-2897","CVE-2013-2899","CVE-2013-4350","CVE-2013-4387"]},{"id":"USN-2038-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-12-03T19:12:49.580783","description":"An information leak was discovered in the handling of ICMPv6 Router\nAdvertisement (RA) messages in the Linux kernel's IPv6 network stack. A\nremote attacker could exploit this flaw to cause a denial of service\n(excessive retries and address-generation outage), and consequently obtain\nsensitive information. (CVE-2013-0343)\n\nA flaw was discovered in the Xen subsystem of the Linux kernel when it\nprovides read-only access to a disk that supports TRIM or SCSI UNMAP to a\nguest OS. A privileged user in the guest OS could exploit this flaw to\ndestroy data on the disk, even though the guest OS should not be able to\nwrite to the disk. (CVE-2013-2140)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem of\nthe Linux kernel. A physically proximate attacker could exploit this flaw\nto execute arbitrary code or cause a denial of service (heap memory\ncorruption) via a specially crafted device that provides an invalid Report\nID. (CVE-2013-2888)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem\nwhen CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could\nleverage this flaw to cause a denial of service via a specially crafted\ndevice. (CVE-2013-2889)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically\nproximate attacker could cause a denial of service (heap out-of-bounds\nwrite) via a specially crafted device. (CVE-2013-2892)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,\nCONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially\nproximate attacker can leverage this flaw to cause a denial of service vias\na specially crafted device. (CVE-2013-2893)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A\nphysically proximate attacker could cause a denial of service (OOPS) or\nobtain sensitive information from kernel memory via a specially crafted\ndevice. (CVE-2013-2895)\n\nKees Cook discovered a vulnerability in the Linux Kernel's Human Interface\nDevice (HID) subsystem's support for N-Trig touch screens. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2896)\n\nKees Cook discovered yet another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A\nphysically proximate attacker could leverage this flaw to cause a denial of\nservice (OOPS) via a specially crafted device. (CVE-2013-2897)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2899)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux","version":"3.2.0-57.87","description":"Linux kernel","is_source":true},{"name":"linux-image-3.2.0-57-highbank","version":"3.2.0-57.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87"},{"name":"linux-image-3.2.0-57-powerpc64-smp","version":"3.2.0-57.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87"},{"name":"linux-image-3.2.0-57-powerpc-smp","version":"3.2.0-57.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87"},{"name":"linux-image-3.2.0-57-generic-pae","version":"3.2.0-57.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87"},{"name":"linux-image-3.2.0-57-virtual","version":"3.2.0-57.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87"},{"name":"linux-image-3.2.0-57-omap","version":"3.2.0-57.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87"},{"name":"linux-image-3.2.0-57-generic","version":"3.2.0-57.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87"}]},"type":"USN","cves_ids":["CVE-2013-0343","CVE-2013-2140","CVE-2013-2888","CVE-2013-2889","CVE-2013-2892","CVE-2013-2893","CVE-2013-2895","CVE-2013-2896","CVE-2013-2897","CVE-2013-2899","CVE-2013-4350","CVE-2013-4387"]},{"id":"USN-2041-1","title":"Linux kernel (Raring HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-12-03T19:25:26.385214","description":"\nA flaw was discovered in the Linux kernel's dm snapshot facility. A remote\nauthenticated user could exploit this flaw to obtain sensitive information\nor modify/corrupt data. (CVE-2013-4299)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n\nA flaw was discovered in the Linux kernel's fib6 error-code encoding for\nIPv6. A local user with the CAT_NET_ADMIN capability could exploit this\nflaw to cause a denial of service (system crash). (CVE-2013-6431)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-raring","version":"3.8.0-34.49~precise1","description":"Linux hardware enablement kernel from Raring","is_source":true},{"name":"linux-image-3.8.0-34-generic","version":"3.8.0-34.49~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-raring","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-raring/3.8.0-34.49~precise1"}]},"type":"USN","cves_ids":["CVE-2013-4299","CVE-2013-4350","CVE-2013-4387","CVE-2013-6431"]},{"id":"USN-2234-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-06-05T21:25:42.518560","description":"Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An\nunprivileged local user could exploit this flaw to cause a denial of\nservice (system crash) or gain administrative privileges. (CVE-2014-3153)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n\nHannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nA flaw was discovered in the Linux kernel's IPC reference counting. An\nunprivileged local user could exploit this flaw to cause a denial of\nservice (OOM system crash). (CVE-2013-4483)\n\nhalfdog reported an error in the AMD K7 and K8 platform support in the\nLinux kernel. An unprivileged local user could exploit this flaw on AMD\nbased systems to cause a denial of service (task kill) or possibly gain\nprivileges via a crafted application. (CVE-2014-1438)\n\nSasha Levin reported a bug in the Linux kernel's virtual memory management\nsubsystem. An unprivileged local user could exploit this flaw to cause a\ndenial of service (system crash). (CVE-2014-3122)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-365.79","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-365-ec2","version":"2.6.32-365.79","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-365.79"}]},"type":"USN","cves_ids":["CVE-2013-4387","CVE-2013-4470","CVE-2013-4483","CVE-2014-1438","CVE-2014-3122","CVE-2014-3153"]},{"id":"USN-2021-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-11-08T21:59:21.490715","description":"An information leak was discovered in the handling of ICMPv6 Router\nAdvertisement (RA) messages in the Linux kernel's IPv6 network stack. A\nremote attacker could exploit this flaw to cause a denial of service\n(excessive retries and address-generation outage), and consequently obtain\nsensitive information. (CVE-2013-0343)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem of\nthe Linux kernel. A physically proximate attacker could exploit this flaw\nto execute arbitrary code or cause a denial of service (heap memory\ncorruption) via a specially crafted device that provides an invalid Report\nID. (CVE-2013-2888)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem\nwhen CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could\nleverage this flaw to cause a denial of service via a specially crafted\ndevice. (CVE-2013-2889)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically\nproximate attacker could cause a denial of service (heap out-of-bounds\nwrite) via a specially crafted device. (CVE-2013-2892)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,\nCONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially\nproximate attacker can leverage this flaw to cause a denial of service vias\na specially crafted device. (CVE-2013-2893)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A\nphysically proximate attacker could cause a denial of service (OOPS) or\nobtain sensitive information from kernel memory via a specially crafted\ndevice. (CVE-2013-2895)\n\nKees Cook discovered a vulnerability in the Linux Kernel's Human Interface\nDevice (HID) subsystem's support for N-Trig touch screens. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2896)\n\nKees Cook discovered yet another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A\nphysically proximate attacker could leverage this flaw to cause a denial of\nservice (OOPS) via a specially crafted device. (CVE-2013-2897)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2899)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux","version":"3.5.0-43.66","description":"Linux kernel","is_source":true},{"name":"linux-image-3.5.0-43-generic","version":"3.5.0-43.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-43.66"},{"name":"linux-image-3.5.0-43-powerpc64-smp","version":"3.5.0-43.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-43.66"},{"name":"linux-image-3.5.0-43-powerpc-smp","version":"3.5.0-43.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-43.66"},{"name":"linux-image-3.5.0-43-omap","version":"3.5.0-43.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-43.66"},{"name":"linux-image-3.5.0-43-highbank","version":"3.5.0-43.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-43.66"}]},"type":"USN","cves_ids":["CVE-2013-0343","CVE-2013-2888","CVE-2013-2889","CVE-2013-2892","CVE-2013-2893","CVE-2013-2895","CVE-2013-2896","CVE-2013-2897","CVE-2013-2899","CVE-2013-4350","CVE-2013-4387"]},{"id":"USN-2045-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-12-03T19:38:31.532852","description":"\nA flaw was discovered in the Linux kernel's dm snapshot facility. A remote\nauthenticated user could exploit this flaw to obtain sensitive information\nor modify/corrupt data. (CVE-2013-4299)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n\nA flaw was discovered in the Linux kernel's fib6 error-code encoding for\nIPv6. A local user with the CAT_NET_ADMIN capability could exploit this\nflaw to cause a denial of service (system crash). (CVE-2013-6431)\n","is_hidden":false,"release_packages":{"raring":[{"name":"linux","version":"3.8.0-34.49","description":"Linux kernel","is_source":true},{"name":"linux-image-3.8.0-34-generic","version":"3.8.0-34.49","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.8.0-34.49"}]},"type":"USN","cves_ids":["CVE-2013-4299","CVE-2013-4350","CVE-2013-4387","CVE-2013-6431"]},{"id":"USN-2022-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-11-08T22:04:41.315025","description":"An information leak was discovered in the handling of ICMPv6 Router\nAdvertisement (RA) messages in the Linux kernel's IPv6 network stack. A\nremote attacker could exploit this flaw to cause a denial of service\n(excessive retries and address-generation outage), and consequently obtain\nsensitive information. (CVE-2013-0343)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem of\nthe Linux kernel. A physically proximate attacker could exploit this flaw\nto execute arbitrary code or cause a denial of service (heap memory\ncorruption) via a specially crafted device that provides an invalid Report\nID. (CVE-2013-2888)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem\nwhen CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could\nleverage this flaw to cause a denial of service via a specially crafted\ndevice. (CVE-2013-2889)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically\nproximate attacker could cause a denial of service (heap out-of-bounds\nwrite) via a specially crafted device. (CVE-2013-2892)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,\nCONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially\nproximate attacker can leverage this flaw to cause a denial of service vias\na specially crafted device. (CVE-2013-2893)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A\nphysically proximate attacker could cause a denial of service (OOPS) or\nobtain sensitive information from kernel memory via a specially crafted\ndevice. (CVE-2013-2895)\n\nKees Cook discovered a vulnerability in the Linux Kernel's Human Interface\nDevice (HID) subsystem's support for N-Trig touch screens. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2896)\n\nKees Cook discovered yet another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A\nphysically proximate attacker could leverage this flaw to cause a denial of\nservice (OOPS) via a specially crafted device. (CVE-2013-2897)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2899)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux-ti-omap4","version":"3.5.0-235.51","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-235-omap4","version":"3.5.0-235.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-235.51"}]},"type":"USN","cves_ids":["CVE-2013-0343","CVE-2013-2888","CVE-2013-2889","CVE-2013-2892","CVE-2013-2893","CVE-2013-2895","CVE-2013-2896","CVE-2013-2897","CVE-2013-2899","CVE-2013-4350","CVE-2013-4387"]},{"id":"USN-2039-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-12-03T19:16:58.109628","description":"An information leak was discovered in the handling of ICMPv6 Router\nAdvertisement (RA) messages in the Linux kernel's IPv6 network stack. A\nremote attacker could exploit this flaw to cause a denial of service\n(excessive retries and address-generation outage), and consequently obtain\nsensitive information. (CVE-2013-0343)\n\nA flaw was discovered in the Xen subsystem of the Linux kernel when it\nprovides read-only access to a disk that supports TRIM or SCSI UNMAP to a\nguest OS. A privileged user in the guest OS could exploit this flaw to\ndestroy data on the disk, even though the guest OS should not be able to\nwrite to the disk. (CVE-2013-2140)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem of\nthe Linux kernel. A physically proximate attacker could exploit this flaw\nto execute arbitrary code or cause a denial of service (heap memory\ncorruption) via a specially crafted device that provides an invalid Report\nID. (CVE-2013-2888)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem\nwhen CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could\nleverage this flaw to cause a denial of service via a specially crafted\ndevice. (CVE-2013-2889)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically\nproximate attacker could cause a denial of service (heap out-of-bounds\nwrite) via a specially crafted device. (CVE-2013-2892)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,\nCONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially\nproximate attacker can leverage this flaw to cause a denial of service vias\na specially crafted device. (CVE-2013-2893)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A\nphysically proximate attacker could cause a denial of service (OOPS) or\nobtain sensitive information from kernel memory via a specially crafted\ndevice. (CVE-2013-2895)\n\nKees Cook discovered a vulnerability in the Linux Kernel's Human Interface\nDevice (HID) subsystem's support for N-Trig touch screens. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2896)\n\nKees Cook discovered yet another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A\nphysically proximate attacker could leverage this flaw to cause a denial of\nservice (OOPS) via a specially crafted device. (CVE-2013-2897)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2899)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-ti-omap4","version":"3.2.0-1441.60","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.2.0-1441-omap4","version":"3.2.0-1441.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1441.60"}]},"type":"USN","cves_ids":["CVE-2013-0343","CVE-2013-2140","CVE-2013-2888","CVE-2013-2889","CVE-2013-2892","CVE-2013-2893","CVE-2013-2895","CVE-2013-2896","CVE-2013-2897","CVE-2013-2899","CVE-2013-4350","CVE-2013-4387"]},{"id":"USN-2050-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-12-07T16:20:36.240075","description":"\nAn information leak was discovered in the handling of ICMPv6 Router\nAdvertisement (RA) messages in the Linux kernel's IPv6 network stack. A\nremote attacker could exploit this flaw to cause a denial of service\n(excessive retries and address-generation outage), and consequently obtain\nsensitive information. (CVE-2013-0343)\n\nDan Carpenter discovered an information leak in the HP Smart Array and\nCompaq SMART2 disk-array driver in the Linux kernel. A local user could\nexploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-2147)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem of\nthe Linux kernel. A physically proximate attacker could exploit this flaw\nto execute arbitrary code or cause a denial of service (heap memory\ncorruption) via a specially crafted device that provides an invalid Report\nID. (CVE-2013-2888)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem\nwhen CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could\nleverage this flaw to cause a denial of service via a specially crafted\ndevice. (CVE-2013-2889)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically\nproximate attacker could cause a denial of service (heap out-of-bounds\nwrite) via a specially crafted device. (CVE-2013-2892)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,\nCONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially\nproximate attacker can leverage this flaw to cause a denial of service vias\na specially crafted device. (CVE-2013-2893)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A\nphysically proximate attacker could cause a denial of service (OOPS) or\nobtain sensitive information from kernel memory via a specially crafted\ndevice. (CVE-2013-2895)\n\nKees Cook discovered a vulnerability in the Linux Kernel's Human Interface\nDevice (HID) subsystem's support for N-Trig touch screens. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2896)\n\nKees Cook discovered yet another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A\nphysically proximate attacker could leverage this flaw to cause a denial of\nservice (OOPS) via a specially crafted device. (CVE-2013-2897)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2899)\n\nA flaw was discovered in the Linux kernel's dm snapshot facility. A remote\nauthenticated user could exploit this flaw to obtain sensitive information\nor modify/corrupt data. (CVE-2013-4299)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n\nHannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nAn information leak was discovered in the Linux kernel's SIOCWANDEV ioctl\ncall. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to obtain potentially sensitive information from kernel memory.\n(CVE-2014-1444)\n\nAn information leak was discovered in the wanxl ioctl function the Linux\nkernel. A local user could exploit this flaw to obtain potentially\nsensitive information from kernel memory. (CVE-2014-1445)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"linux-ti-omap4","version":"3.5.0-236.52","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-236-omap4","version":"3.5.0-236.52","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-236.52"}]},"type":"USN","cves_ids":["CVE-2013-0343","CVE-2013-2147","CVE-2013-2888","CVE-2013-2889","CVE-2013-2892","CVE-2013-2893","CVE-2013-2895","CVE-2013-2896","CVE-2013-2897","CVE-2013-2899","CVE-2013-4299","CVE-2013-4350","CVE-2013-4387","CVE-2013-4470","CVE-2014-1444","CVE-2014-1445"]},{"id":"USN-2233-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-06-05T21:22:45.765630","description":"Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An\nunprivileged local user could exploit this flaw to cause a denial of\nservice (system crash) or gain administrative privileges. (CVE-2014-3153)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n\nHannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nA flaw was discovered in the Linux kernel's IPC reference counting. An\nunprivileged local user could exploit this flaw to cause a denial of\nservice (OOM system crash). (CVE-2013-4483)\n\nhalfdog reported an error in the AMD K7 and K8 platform support in the\nLinux kernel. An unprivileged local user could exploit this flaw on AMD\nbased systems to cause a denial of service (task kill) or possibly gain\nprivileges via a crafted application. (CVE-2014-1438)\n\nSasha Levin reported a bug in the Linux kernel's virtual memory management\nsubsystem. An unprivileged local user could exploit this flaw to cause a\ndenial of service (system crash). (CVE-2014-3122)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-61.124","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-61-preempt","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-powerpc-smp","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-ia64","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-generic-pae","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-virtual","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-lpia","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-386","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-sparc64-smp","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-generic","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-powerpc","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-sparc64","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-powerpc64-smp","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-server","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"},{"name":"linux-image-2.6.32-61-versatile","version":"2.6.32-61.124","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-61.124"}]},"type":"USN","cves_ids":["CVE-2013-4387","CVE-2013-4470","CVE-2013-4483","CVE-2014-1438","CVE-2014-3122","CVE-2014-3153"]},{"id":"USN-2024-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-11-08T22:14:49.527356","description":"An information leak was discovered in the handling of ICMPv6 Router\nAdvertisement (RA) messages in the Linux kernel's IPv6 network stack. A\nremote attacker could exploit this flaw to cause a denial of service\n(excessive retries and address-generation outage), and consequently obtain\nsensitive information. (CVE-2013-0343)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem of\nthe Linux kernel. A physically proximate attacker could exploit this flaw\nto execute arbitrary code or cause a denial of service (heap memory\ncorruption) via a specially crafted device that provides an invalid Report\nID. (CVE-2013-2888)\n\nKees Cook discovered flaw in the Human Interface Device (HID) subsystem\nwhen CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could\nleverage this flaw to cause a denial of service via a specially crafted\ndevice. (CVE-2013-2889)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically\nproximate attacker could cause a denial of service (heap out-of-bounds\nwrite) via a specially crafted device. (CVE-2013-2892)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,\nCONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially\nproximate attacker can leverage this flaw to cause a denial of service vias\na specially crafted device. (CVE-2013-2893)\n\nKees Cook discovered another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A\nphysically proximate attacker could cause a denial of service (OOPS) or\nobtain sensitive information from kernel memory via a specially crafted\ndevice. (CVE-2013-2895)\n\nKees Cook discovered a vulnerability in the Linux Kernel's Human Interface\nDevice (HID) subsystem's support for N-Trig touch screens. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2896)\n\nKees Cook discovered yet another flaw in the Human Interface Device (HID)\nsubsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A\nphysically proximate attacker could leverage this flaw to cause a denial of\nservice (OOPS) via a specially crafted device. (CVE-2013-2897)\n\nKees Cook discovered a flaw in the Human Interface Device (HID) subsystem\nof the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically\nproximate attacker could exploit this flaw to cause a denial of service\n(OOPS) via a specially crafted device. (CVE-2013-2899)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n","is_hidden":false,"release_packages":{"raring":[{"name":"linux-ti-omap4","version":"3.5.0-235.51","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-235-omap4","version":"3.5.0-235.51","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-235.51"}]},"type":"USN","cves_ids":["CVE-2013-0343","CVE-2013-2888","CVE-2013-2889","CVE-2013-2892","CVE-2013-2893","CVE-2013-2895","CVE-2013-2896","CVE-2013-2897","CVE-2013-2899","CVE-2013-4350","CVE-2013-4387"]},{"id":"USN-2049-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-12-07T15:54:49.228291","description":"\nMiroslav Vadkerti discovered a flaw in how the permissions for network\nsysctls are handled in the Linux kernel. An unprivileged local user could\nexploit this flaw to have privileged access to files in /proc/sys/net/.\n(CVE-2013-4270)\n\nA flaw was discovered in the Linux kernel's dm snapshot facility. A remote\nauthenticated user could exploit this flaw to obtain sensitive information\nor modify/corrupt data. (CVE-2013-4299)\n\nWannes Rombouts reported a vulnerability in the networking tuntap interface\nof the Linux kernel. A local user with the CAP_NET_ADMIN capability could\nleverage this flaw to gain full admin privileges. (CVE-2013-4343)\n\nAlan Chester reported a flaw in the IPv6 Stream Control Transmission\nProtocol (SCTP) of the Linux kernel. A remote attacker could exploit this\nflaw to obtain sensitive information by sniffing network traffic.\n(CVE-2013-4350)\n\nDmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP\nFragmentation Offload (UFO) processing. A remote attacker could leverage\nthis flaw to cause a denial of service (system crash). (CVE-2013-4387)\n\nHannes Frederic Sowa discovered a flaw in the Linux kernel's UDP\nFragmentation Offload (UFO). An unprivileged local user could exploit this\nflaw to cause a denial of service (system crash) or possibly gain\nadministrative privileges. (CVE-2013-4470)\n\nA flaw was discovered in the Linux kernel's fib6 error-code encoding for\nIPv6. A local user with the CAT_NET_ADMIN capability could exploit this\nflaw to cause a denial of service (system crash). (CVE-2013-6431)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n\nAn information leak was discovered in the Linux kernel's SIOCWANDEV ioctl\ncall. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to obtain potentially sensitive information from kernel memory.\n(CVE-2014-1444)\n\nAn information leak was discovered in the wanxl ioctl function the Linux\nkernel. A local user could exploit this flaw to obtain potentially\nsensitive information from kernel memory. (CVE-2014-1445)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"linux","version":"3.11.0-14.21","description":"Linux kernel","is_source":true},{"name":"linux-image-3.11.0-14-generic","version":"3.11.0-14.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.11.0-14.21"},{"name":"linux-image-3.11.0-14-generic-lpae","version":"3.11.0-14.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.11.0-14.21"}]},"type":"USN","cves_ids":["CVE-2013-4270","CVE-2013-4299","CVE-2013-4343","CVE-2013-4350","CVE-2013-4387","CVE-2013-4470","CVE-2013-6431","CVE-2013-7027","CVE-2014-1444","CVE-2014-1445"]}]},{"id":"CVE-2013-4345","published":"2013-10-10T00:00:00","updated_at":"2026-07-04T07:36:12.966678+00:00","description":"\nOff-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in\nthe Linux kernel through 3.11.4 makes it easier for context-dependent\nattackers to defeat cryptographic protection mechanisms via multiple\nrequests for small amounts of data, leading to improper management of the\nstate of the consumed data.","ubuntu_description":"\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=linux-crypto-vger&m=137942122902845&w=2","https://ubuntu.com/security/notices/USN-2064-1","https://ubuntu.com/security/notices/USN-2065-1","https://ubuntu.com/security/notices/USN-2068-1","https://ubuntu.com/security/notices/USN-2070-1","https://ubuntu.com/security/notices/USN-2071-1","https://ubuntu.com/security/notices/USN-2072-1","https://ubuntu.com/security/notices/USN-2074-1","https://ubuntu.com/security/notices/USN-2075-1","https://ubuntu.com/security/notices/USN-2076-1","https://ubuntu.com/security/notices/USN-2109-1","https://ubuntu.com/security/notices/USN-2110-1","https://ubuntu.com/security/notices/USN-2158-1","https://www.cve.org/CVERecord?id=CVE-2013-4345"],"bugs":["https://launchpad.net/bugs/1229981"],"patches":{"linux":["break-fix: - 714b33d15130cbb5ab426456d4e3de842d6c5b8a"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-fsl-imx51":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-55.117","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-59.90","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-45.68","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"3.11.0-15.23","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.12.0-5.13","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1630.42","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-1626.35","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-360.73","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.5.0-45.68~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.8.0-38.56~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.11.0-15.23~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1443.62","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-237.53","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"3.5.0-237.53","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"3.5.0-237.53","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.13~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2071-1","USN-2158-1","USN-2110-1","USN-2075-1","USN-2074-1","USN-2076-1","USN-2068-1","USN-2109-1","USN-2064-1","USN-2070-1","USN-2072-1","USN-2065-1"],"notices":[{"id":"USN-2071-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:58:15.740705","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux","version":"3.5.0-45.68","description":"Linux kernel","is_source":true},{"name":"linux-image-3.5.0-45-omap","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-generic","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-highbank","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-powerpc-smp","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"},{"name":"linux-image-3.5.0-45-powerpc64-smp","version":"3.5.0-45.68","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2158-1","title":"Linux kernel (Raring HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-04-01T05:21:48.622608","description":"Stephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nNico Golde and Fabian Yamaguchi reported buffer underflow errors in the\nimplementation of the XFS filesystem in the Linux kernel. A local user with\nCAP_SYS_ADMIN could exploit these flaw to cause a denial of service (memory\ncorruption) or possibly other unspecified issues. (CVE-2013-6382)\n\nAn information leak was discovered in the Linux kernel when built with the\nNetFilter Connection Tracking (NF_CONNTRACK) support for IRC protocol\n(NF_NAT_IRC). A remote attacker could exploit this flaw to obtain\npotentially sensitive kernel information when communicating over a client-\nto-client IRC connection(/dcc) via a NAT-ed network. (CVE-2014-1690)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-raring","version":"3.8.0-38.56~precise1","description":"Linux hardware enablement kernel from Raring","is_source":true},{"name":"linux-image-3.8.0-38-generic","version":"3.8.0-38.56~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-raring","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-raring/3.8.0-38.56~precise1"}]},"type":"USN","cves_ids":["CVE-2013-4345","CVE-2013-6382","CVE-2014-1690"]},{"id":"USN-2110-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-02-18T22:19:31.484031","description":"\nVasily Kulikov reported a flaw in the Linux kernel's implementation of\nptrace. An unprivileged local user could exploit this flaw to obtain\nsensitive information from kernel memory. (CVE-2013-2929)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nAndrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu\nfunction of the Kernel Virtual Machine (KVM) subsystem. A local user could\nexploit this flaw to gain privileges on the host machine. (CVE-2013-4587)\n\nAndrew Honig reported a flaw in the apic_get_tmcct function of the Kernel\nVirtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could\nexploit this flaw to cause a denial of service or host OS system crash.\n(CVE-2013-6367)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec\nAACRAID scsi raid devices in the Linux kernel. A local user could use this\nflaw to cause a denial of service or possibly other unspecified impact.\n(CVE-2013-6380)\n\nNico Golde and Fabian Yamaguchi reported buffer underflow errors in the\nimplementation of the XFS filesystem in the Linux kernel. A local user with\nCAP_SYS_ADMIN could exploit these flaw to cause a denial of service (memory\ncorruption) or possibly other unspecified issues. (CVE-2013-6382)\n\nmpd reported an information leak in the recvfrom, recvmmsg, and recvmsg\nsystem calls in the Linux kernel. An unprivileged local user could exploit\nthis flaw to obtain sensitive information from kernel stack memory.\n(CVE-2013-7263)\n\nmpb reported an information leak in the Layer Two Tunneling Protocol (l2tp)\nof the Linux kernel. A local user could exploit this flaw to obtain\nsensitive information from kernel stack memory. (CVE-2013-7264)\n\nmpb reported an information leak in the Phone Network protocol (phonet) in\nthe Linux kernel. A local user could exploit this flaw to obtain sensitive\ninformation from kernel stack memory. (CVE-2013-7265)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with ISDN sockets in the Linux kernel. A local user\ncould exploit this leak to obtain potentially sensitive information from\nkernel memory. (CVE-2013-7266)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with apple talk sockets in the Linux kernel. A local\nuser could exploit this leak to obtain potentially sensitive information\nfrom kernel memory. (CVE-2013-7267)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with ipx protocol sockets in the Linux kernel. A\nlocal user could exploit this leak to obtain potentially sensitive\ninformation from kernel memory. (CVE-2013-7268)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with the netrom address family in the Linux kernel. A\nlocal user could exploit this leak to obtain potentially sensitive\ninformation from kernel memory. (CVE-2013-7269)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with packet address family sockets in the Linux\nkernel. A local user could exploit this leak to obtain potentially\nsensitive information from kernel memory. (CVE-2013-7270)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with x25 protocol sockets in the Linux kernel. A\nlocal user could exploit this leak to obtain potentially sensitive\ninformation from kernel memory. (CVE-2013-7271)\n\nmpb reported an information leak in the Low-Rate Wireless Personal Area\nNetworks support (IEEE 802.15.4) in the Linux kernel. A local user could\nexploit this flaw to obtain sensitive information from kernel stack memory.\n(CVE-2013-7281)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-ti-omap4","version":"3.2.0-1443.62","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.2.0-1443-omap4","version":"3.2.0-1443.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1443.62"}]},"type":"USN","cves_ids":["CVE-2013-2929","CVE-2013-4345","CVE-2013-4348","CVE-2013-4587","CVE-2013-6367","CVE-2013-6380","CVE-2013-6382","CVE-2013-7263","CVE-2013-7264","CVE-2013-7265","CVE-2013-7266","CVE-2013-7267","CVE-2013-7268","CVE-2013-7269","CVE-2013-7270","CVE-2013-7271","CVE-2013-7281"]},{"id":"USN-2075-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T11:07:55.631603","description":"Vasily Kulikov reported a flaw in the Linux kernel's implementation of\nptrace. An unprivileged local user could exploit this flaw to obtain\nsensitive information from kernel memory. (CVE-2013-2929)\n\nDave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for the SystemBase Multi-2/PCI serial card. An unprivileged user\ncould obtain sensitive information from kernel memory. (CVE-2013-4516)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec\nAACRAID scsi raid devices in the Linux kernel. A local user could use this\nflaw to cause a denial of service or possibly other unspecified impact.\n(CVE-2013-6380)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nA race condition flaw was discovered in the Linux kernel's ipc shared\nmemory implimentation. A local user could exploit this flaw to cause a\ndenial of service (system crash) or possibly have unspecied other impacts.\n(CVE-2013-7026)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"linux","version":"3.11.0-15.23","description":"Linux kernel","is_source":true},{"name":"linux-image-3.11.0-15-generic-lpae","version":"3.11.0-15.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.11.0-15.23"},{"name":"linux-image-3.11.0-15-generic","version":"3.11.0-15.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.11.0-15.23"}]},"type":"USN","cves_ids":["CVE-2013-2929","CVE-2013-2930","CVE-2013-4345","CVE-2013-4348","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-4516","CVE-2013-6378","CVE-2013-6380","CVE-2013-6383","CVE-2013-6763","CVE-2013-7026"]},{"id":"USN-2074-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T11:11:02.159414","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"raring":[{"name":"linux-ti-omap4","version":"3.5.0-237.53","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-237-omap4","version":"3.5.0-237.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2076-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T11:12:05.627099","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"saucy":[{"name":"linux-ti-omap4","version":"3.5.0-237.53","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-237-omap4","version":"3.5.0-237.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2068-1","title":"Linux kernel (Quantal HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:51:28.340288","description":"\nDave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-quantal","version":"3.5.0-45.68~precise1","description":"Linux hardware enablement kernel from Quantal","is_source":true},{"name":"linux-image-3.5.0-45-generic","version":"3.5.0-45.68~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-45.68~precise1"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4348","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2109-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-02-18T22:12:51.592262","description":"\nVasily Kulikov reported a flaw in the Linux kernel's implementation of\nptrace. An unprivileged local user could exploit this flaw to obtain\nsensitive information from kernel memory. (CVE-2013-2929)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nAndrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu\nfunction of the Kernel Virtual Machine (KVM) subsystem. A local user could\nexploit this flaw to gain privileges on the host machine. (CVE-2013-4587)\n\nAndrew Honig reported a flaw in the apic_get_tmcct function of the Kernel\nVirtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could\nexploit this flaw to cause a denial of service or host OS system crash.\n(CVE-2013-6367)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec\nAACRAID scsi raid devices in the Linux kernel. A local user could use this\nflaw to cause a denial of service or possibly other unspecified impact.\n(CVE-2013-6380)\n\nNico Golde and Fabian Yamaguchi reported buffer underflow errors in the\nimplementation of the XFS filesystem in the Linux kernel. A local user with\nCAP_SYS_ADMIN could exploit these flaw to cause a denial of service (memory\ncorruption) or possibly other unspecified issues. (CVE-2013-6382)\n\nmpd reported an information leak in the recvfrom, recvmmsg, and recvmsg\nsystem calls in the Linux kernel. An unprivileged local user could exploit\nthis flaw to obtain sensitive information from kernel stack memory.\n(CVE-2013-7263)\n\nmpb reported an information leak in the Layer Two Tunneling Protocol (l2tp)\nof the Linux kernel. A local user could exploit this flaw to obtain\nsensitive information from kernel stack memory. (CVE-2013-7264)\n\nmpb reported an information leak in the Phone Network protocol (phonet) in\nthe Linux kernel. A local user could exploit this flaw to obtain sensitive\ninformation from kernel stack memory. (CVE-2013-7265)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with ISDN sockets in the Linux kernel. A local user\ncould exploit this leak to obtain potentially sensitive information from\nkernel memory. (CVE-2013-7266)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with apple talk sockets in the Linux kernel. A local\nuser could exploit this leak to obtain potentially sensitive information\nfrom kernel memory. (CVE-2013-7267)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with ipx protocol sockets in the Linux kernel. A\nlocal user could exploit this leak to obtain potentially sensitive\ninformation from kernel memory. (CVE-2013-7268)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with the netrom address family in the Linux kernel. A\nlocal user could exploit this leak to obtain potentially sensitive\ninformation from kernel memory. (CVE-2013-7269)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with packet address family sockets in the Linux\nkernel. A local user could exploit this leak to obtain potentially\nsensitive information from kernel memory. (CVE-2013-7270)\n\nAn information leak was discovered in the recvfrom, recvmmsg, and recvmsg\nsystemcalls when used with x25 protocol sockets in the Linux kernel. A\nlocal user could exploit this leak to obtain potentially sensitive\ninformation from kernel memory. (CVE-2013-7271)\n\nmpb reported an information leak in the Low-Rate Wireless Personal Area\nNetworks support (IEEE 802.15.4) in the Linux kernel. A local user could\nexploit this flaw to obtain sensitive information from kernel stack memory.\n(CVE-2013-7281)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux","version":"3.2.0-59.90","description":"Linux kernel","is_source":true},{"name":"linux-image-3.2.0-59-generic","version":"3.2.0-59.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-59.90"},{"name":"linux-image-3.2.0-59-virtual","version":"3.2.0-59.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-59.90"},{"name":"linux-image-3.2.0-59-generic-pae","version":"3.2.0-59.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-59.90"},{"name":"linux-image-3.2.0-59-powerpc64-smp","version":"3.2.0-59.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-59.90"},{"name":"linux-image-3.2.0-59-highbank","version":"3.2.0-59.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-59.90"},{"name":"linux-image-3.2.0-59-omap","version":"3.2.0-59.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-59.90"},{"name":"linux-image-3.2.0-59-powerpc-smp","version":"3.2.0-59.90","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-59.90"}]},"type":"USN","cves_ids":["CVE-2013-2929","CVE-2013-4345","CVE-2013-4348","CVE-2013-4587","CVE-2013-6367","CVE-2013-6380","CVE-2013-6382","CVE-2013-7263","CVE-2013-7264","CVE-2013-7265","CVE-2013-7266","CVE-2013-7267","CVE-2013-7268","CVE-2013-7269","CVE-2013-7270","CVE-2013-7271","CVE-2013-7281"]},{"id":"USN-2064-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:13:29.614795","description":"Stephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nA flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)\nsupport. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to gain additional administrative privileges. (CVE-2013-4588)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-55.117","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-55-lpia","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-powerpc64-smp","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-generic-pae","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-versatile","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-generic","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-virtual","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-ia64","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-powerpc-smp","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-386","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-powerpc","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-server","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-sparc64","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-sparc64-smp","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"},{"name":"linux-image-2.6.32-55-preempt","version":"2.6.32-55.117","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117"}]},"type":"USN","cves_ids":["CVE-2013-4345","CVE-2013-4588","CVE-2013-6378","CVE-2013-6763"]},{"id":"USN-2070-1","title":"Linux kernel (Saucy HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:55:40.391340","description":"Vasily Kulikov reported a flaw in the Linux kernel's implementation of\nptrace. An unprivileged local user could exploit this flaw to obtain\nsensitive information from kernel memory. (CVE-2013-2929)\n\nDave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nJason Wang discovered a bug in the network flow dissector in the Linux\nkernel. A remote attacker could exploit this flaw to cause a denial of\nservice (infinite loop). (CVE-2013-4348)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for the SystemBase Multi-2/PCI serial card. An unprivileged user\ncould obtain sensitive information from kernel memory. (CVE-2013-4516)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec\nAACRAID scsi raid devices in the Linux kernel. A local user could use this\nflaw to cause a denial of service or possibly other unspecified impact.\n(CVE-2013-6380)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nA race condition flaw was discovered in the Linux kernel's ipc shared\nmemory implimentation. A local user could exploit this flaw to cause a\ndenial of service (system crash) or possibly have unspecied other impacts.\n(CVE-2013-7026)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-saucy","version":"3.11.0-15.23~precise1","description":"Linux hardware enablement kernel from Saucy","is_source":true},{"name":"linux-image-3.11.0-15-generic-lpae","version":"3.11.0-15.23~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-15.23~precise1"},{"name":"linux-image-3.11.0-15-generic","version":"3.11.0-15.23~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-15.23~precise1"}]},"type":"USN","cves_ids":["CVE-2013-2929","CVE-2013-2930","CVE-2013-4345","CVE-2013-4348","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-4516","CVE-2013-6378","CVE-2013-6380","CVE-2013-6383","CVE-2013-6763","CVE-2013-7026"]},{"id":"USN-2072-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:59:49.262411","description":"Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event\nsubsystem that allows normal users to enable function tracing. An\nunprivileged local user could exploit this flaw to obtain potentially\nsensitive information from the kernel. (CVE-2013-2930)\n\nStephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nMultiple integer overflow flaws were discovered in the Alchemy LCD frame-\nbuffer drivers in the Linux kernel. An unprivileged local user could\nexploit this flaw to gain administrative privileges. (CVE-2013-4511)\n\nNico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo\nDevices USB over WiFi devices. A local user could exploit this flaw to\ncause a denial of service or possibly unspecified impact. (CVE-2013-4513)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Agere Systems HERMES II Wireless PC Cards. A local user with the\nCAP_NET_ADMIN capability could exploit this flaw to cause a denial of\nservice or possibly gain adminstrative priviliges. (CVE-2013-4514)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndriver for Beceem WIMAX chipset based devices. An unprivileged local user\ncould exploit this flaw to obtain sensitive information from kernel memory.\n(CVE-2013-4515)\n\nA flaw was discovered in the Linux kernel's compat ioctls for Adaptec\nAACRAID scsi raid devices. An unprivileged local user could send\nadministrative commands to these devices potentially compromising the data\nstored on the device. (CVE-2013-6383)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n\nEvan Huus reported a buffer overflow in the Linux kernel's radiotap header\nparsing. A remote attacker could cause a denial of service (buffer over-\nread) via a specially crafted header. (CVE-2013-7027)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux-ti-omap4","version":"3.5.0-237.53","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-237-omap4","version":"3.5.0-237.53","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53"}]},"type":"USN","cves_ids":["CVE-2013-2930","CVE-2013-4345","CVE-2013-4511","CVE-2013-4513","CVE-2013-4514","CVE-2013-4515","CVE-2013-6383","CVE-2013-6763","CVE-2013-7027"]},{"id":"USN-2065-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2014-01-03T10:29:27.276183","description":"Stephan Mueller reported an error in the Linux kernel's ansi cprng random\nnumber generator. This flaw makes it easier for a local attacker to break\ncryptographic protections. (CVE-2013-4345)\n\nA flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)\nsupport. A local user with the CAP_NET_ADMIN capability could exploit this\nflaw to gain additional administrative privileges. (CVE-2013-4588)\n\nNico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's\ndebugfs filesystem. An administrative local user could exploit this flaw to\ncause a denial of service (OOPS). (CVE-2013-6378)\n\nNico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.\nA local user could exploit this flaw to cause a denial of service (memory\ncorruption) or possibly gain privileges. (CVE-2013-6763)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-360.73","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-360-ec2","version":"2.6.32-360.73","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-360.73"}]},"type":"USN","cves_ids":["CVE-2013-4345","CVE-2013-4588","CVE-2013-6378","CVE-2013-6763"]}]},{"id":"CVE-2013-4356","published":"2013-10-09T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nXen 4.3.x writes hypervisor mappings to certain shadow pagetables when live\nmigration is performed on hosts with more than 5TB of RAM, which allows\nlocal 64-bit PV guests to read or write to invalid memory and cause a\ndenial of service (crash).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this is XSA-64\nonly affects 4.3+"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.xen.org/archives/html/xen-announce/2013-09/msg00007.html","https://www.cve.org/CVERecord?id=CVE-2013-4356"],"bugs":[""],"patches":{"xen-3.3":[],"xen":[]},"tags":{"xen-3.3":["universe-binary"],"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"only 4.3+","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"only 4.3+","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"only 4.3+","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"4.3.0-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.3","source":"https://ubuntu.com/security/cve?package=xen-3.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.3","debian":"https://tracker.debian.org/pkg/xen-3.3","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4385","published":"2013-10-09T14:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the \"read-string!\" procedure in the \"extras\" unit in\nCHICKEN stable before 4.8.0.5 and development snapshots before 4.8.3 allows\nremote attackers to cause a denial of service (memory corruption and\napplication crash) and possibly execute arbitrary code via a \"#f\" value in\nthe NUM argument.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=commit;h=cd1b9775005ebe220ba11265dbf5396142e65f26","http://www.openwall.com/lists/oss-security/2013/09/26/7","http://lists.nongnu.org/archive/html/chicken-announce/2013-09/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2013-4385"],"bugs":[""],"patches":{"chicken":["upstream: http://code.call-cc.org/cgi-bin/gitweb.cgi?p=chicken-core.git;a=commit;h=cd1b9775005ebe220ba11265dbf5396142e65f26"]},"tags":{},"packages":[{"name":"chicken","source":"https://ubuntu.com/security/cve?package=chicken","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chicken","debian":"https://tracker.debian.org/pkg/chicken","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.8.0.5-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.8.0.5, 4.8.3","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0.5-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.8.0.5-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4258","published":"2013-10-09T14:54:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nFormat string vulnerability in the osLogMsg function in server/os/aulog.c\nin Network Audio System (NAS) 1.9.3 allows remote attackers to cause a\ndenial of service (crash) and possibly execute arbitrary code via format\nstring specifiers in unspecified vectors, related to syslog.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this got fixed in debian/ubuntu 1.9.3-2"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://radscan.com/pipermail/nas/2013-August/001270.html","https://www.cve.org/CVERecord?id=CVE-2013-4258"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=720287"],"patches":{"nas":["upstream: http://sourceforge.net/p/nas/code/285"]},"tags":{},"packages":[{"name":"nas","source":"https://ubuntu.com/security/cve?package=nas","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nas","debian":"https://tracker.debian.org/pkg/nas","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2098","published":"2013-10-09T14:53:00","updated_at":"2025-08-04T19:24:20.732475+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2013-2099. Reason: This candidate is a duplicate of CVE-2013-2099.\nNotes: All CVE users should reference CVE-2013-2099 instead of this\ncandidate. All references and descriptions in this candidate have been\nremoved to prevent accidental usage","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This CVE is for the python-backports-ssl_match_hostname\npackage. CVE-2013-2099 is for python itself."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/05/16/5","https://bugzilla.redhat.com/show_bug.cgi?id=963260","https://www.cve.org/CVERecord?id=CVE-2013-2098"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=963186","https://bugs.launchpad.net/ubuntu/+source/bzr/+bug/1182124","http://bugs.python.org/issue17980"],"patches":{"python2.6":[]},"tags":{},"packages":[{"name":"python2.6","source":"https://ubuntu.com/security/cve?package=python2.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.6","debian":"https://tracker.debian.org/pkg/python2.6","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4332","published":"2013-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple integer overflows in malloc/malloc.c in the GNU C Library (aka\nglibc or libc6) 2.18 and earlier allow context-dependent attackers to cause\na denial of service (heap corruption) via a large value to the (1) pvalloc,\n(2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc\nfunctions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1991-1","https://www.cve.org/CVERecord?id=CVE-2013-4332"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=722536","https://sourceware.org/bugzilla/show_bug.cgi?id=15855","https://sourceware.org/bugzilla/show_bug.cgi?id=15856","https://sourceware.org/bugzilla/show_bug.cgi?id=15857"],"patches":{"eglibc":["upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=1159a193696ad48ec86e5895f6dee3e539619c0e","upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=55e17aadc1ef17a1df9626fb0e9fba290ece3331","upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=b73ed247781d533628b681f57257dc85882645d3"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"lucid","status":"released","description":"2.11.1-0ubuntu7.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.15-0ubuntu20.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2.17-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2.17-93ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.17-93","component":null,"pocket":"security"}]}],"notices_ids":["USN-1991-1"],"notices":[{"id":"USN-1991-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-10-21T16:20:34.407898","description":"It was discovered that the GNU C Library incorrectly handled the strcoll()\nfunction. An attacker could use this issue to cause a denial of service, or\npossibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)\n\nIt was discovered that the GNU C Library incorrectly handled multibyte\ncharacters in the regular expression matcher. An attacker could use this\nissue to cause a denial of service. (CVE-2013-0242)\n\nIt was discovered that the GNU C Library incorrectly handled large numbers\nof domain conversion results in the getaddrinfo() function. An attacker\ncould use this issue to cause a denial of service. (CVE-2013-1914)\n\nIt was discovered that the GNU C Library readdir_r() function incorrectly\nhandled crafted NTFS or CIFS images. An attacker could use this issue to\ncause a denial of service, or possibly execute arbitrary code.\n(CVE-2013-4237)\n\nIt was discovered that the GNU C Library incorrectly handled memory\nallocation. An attacker could use this issue to cause a denial of service.\n(CVE-2013-4332)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.5","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.5"}],"lucid":[{"name":"eglibc","version":"2.11.1-0ubuntu7.13","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.11.1-0ubuntu7.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.11.1-0ubuntu7.13"}],"quantal":[{"name":"eglibc","version":"2.15-0ubuntu20.2","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu20.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu20.2"}],"raring":[{"name":"eglibc","version":"2.17-0ubuntu5.1","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.17-0ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.17-0ubuntu5.1"}]},"type":"USN","cves_ids":["CVE-2012-4412","CVE-2012-4424","CVE-2013-0242","CVE-2013-1914","CVE-2013-4237","CVE-2013-4332"]}]},{"id":"CVE-2013-4237","published":"2013-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18\nand earlier allows context-dependent attackers to cause a denial of service\n(out-of-bounds write and crash) or possibly execute arbitrary code via a\ncrafted (1) NTFS or (2) CIFS image.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"may only affect powerpc in practice"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://sourceware.org/ml/libc-alpha/2013-05/msg00445.html","https://ubuntu.com/security/notices/USN-1991-1","https://www.cve.org/CVERecord?id=CVE-2013-4237"],"bugs":["http://sourceware.org/bugzilla/show_bug.cgi?id=14699","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=719558"],"patches":{"eglibc":["other: http://sourceware.org/ml/libc-alpha/2013-05/msg00445.html","upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=91ce40854d0b7f865cf5024ef95a8026b76096f3"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"lucid","status":"released","description":"2.11.1-0ubuntu7.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.15-0ubuntu20.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2.17-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.17-93ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1991-1"],"notices":[{"id":"USN-1991-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-10-21T16:20:34.407898","description":"It was discovered that the GNU C Library incorrectly handled the strcoll()\nfunction. An attacker could use this issue to cause a denial of service, or\npossibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)\n\nIt was discovered that the GNU C Library incorrectly handled multibyte\ncharacters in the regular expression matcher. An attacker could use this\nissue to cause a denial of service. (CVE-2013-0242)\n\nIt was discovered that the GNU C Library incorrectly handled large numbers\nof domain conversion results in the getaddrinfo() function. An attacker\ncould use this issue to cause a denial of service. (CVE-2013-1914)\n\nIt was discovered that the GNU C Library readdir_r() function incorrectly\nhandled crafted NTFS or CIFS images. An attacker could use this issue to\ncause a denial of service, or possibly execute arbitrary code.\n(CVE-2013-4237)\n\nIt was discovered that the GNU C Library incorrectly handled memory\nallocation. An attacker could use this issue to cause a denial of service.\n(CVE-2013-4332)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.5","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.5"}],"lucid":[{"name":"eglibc","version":"2.11.1-0ubuntu7.13","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.11.1-0ubuntu7.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.11.1-0ubuntu7.13"}],"quantal":[{"name":"eglibc","version":"2.15-0ubuntu20.2","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu20.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu20.2"}],"raring":[{"name":"eglibc","version":"2.17-0ubuntu5.1","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.17-0ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.17-0ubuntu5.1"}]},"type":"USN","cves_ids":["CVE-2012-4412","CVE-2012-4424","CVE-2013-0242","CVE-2013-1914","CVE-2013-4237","CVE-2013-4332"]}]},{"id":"CVE-2013-2207","published":"2013-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not\nproperly check permissions for tty files, which allows local users to\nchange the permission on the files and obtain access to arbitrary\npseudo-terminals by leveraging a FUSE file system.","ubuntu_description":"\nMartin Carpenter discovered that pt_chown in the GNU C Library\ndid not properly check permissions for tty files. A local attacker\ncould use this to gain administrative privileges or expose sensitive\ninformation.","notes":[{"author":"mdeslaur","note":"patch disables building of pt_chown\nWe can't just remove pt_chown from older releases, as\nunfortunately a lot of stuff still needs it, like lxc for\nexample. We'll need to identify them first and fix them at the\nsame time.\n\nWhile this CVE was originally marked as fixed in 2.17-93ubuntu2,\nit got reverted in 2.17-93ubuntu4."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2985-1","https://www.cve.org/CVERecord?id=CVE-2013-2207"],"bugs":["http://sourceware.org/bugzilla/show_bug.cgi?id=15755","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=717544","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2207"],"patches":{"eglibc":["upstream: http://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commitdiff;h=e4608715e6e1dd2adc91982fd151d5ba4f761d69"],"glibc":[]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.14","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.19-0ubuntu6.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"2.21-0ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.23-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.23-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.23-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2985-1"],"notices":[{"id":"USN-2985-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to\nmake all the necessary changes.\n","references":[],"published":"2016-05-25T20:22:47.670239","description":"Martin Carpenter discovered that pt_chown in the GNU C Library did not\nproperly check permissions for tty files. A local attacker could use this\nto gain administrative privileges or expose sensitive information.\n(CVE-2013-2207, CVE-2016-2856)\n\nRobin Hack discovered that the Name Service Switch (NSS) implementation in\nthe GNU C Library did not properly manage its file descriptors. An attacker\ncould use this to cause a denial of service (infinite loop).\n(CVE-2014-8121)\n\nJoseph Myers discovered that the GNU C Library did not properly handle long\narguments to functions returning a representation of Not a Number (NaN). An\nattacker could use this to cause a denial of service (stack exhaustion\nleading to an application crash) or possibly execute arbitrary code.\n(CVE-2014-9761)\n\nArjun Shankar discovered that in certain situations the nss_dns code in the\nGNU C Library did not properly account buffer sizes when passed an\nunaligned buffer. An attacker could use this to cause a denial of service\nor possibly execute arbitrary code. (CVE-2015-1781)\n\nSumit Bose and Lukas Slebodnik discovered that the Name Service\nSwitch (NSS) implementation in the GNU C Library did not handle long\nlines in the files databases correctly. A local attacker could use\nthis to cause a denial of service (application crash) or possibly\nexecute arbitrary code. (CVE-2015-5277)\n\nAdam Nielsen discovered that the strftime function in the GNU C Library did\nnot properly handle out-of-range argument data. An attacker could use this\nto cause a denial of service (application crash) or possibly expose\nsensitive information. (CVE-2015-8776)\n\nHector Marco and Ismael Ripoll discovered that the GNU C Library allowed\nthe pointer-guarding protection mechanism to be disabled by honoring the\nLD_POINTER_GUARD environment variable across privilege boundaries. A local\nattacker could use this to exploit an existing vulnerability more easily.\n(CVE-2015-8777)\n\nSzabolcs Nagy discovered that the hcreate functions in the GNU C Library\ndid not properly check its size argument, leading to an integer overflow.\nAn attacker could use to cause a denial of service (application crash) or\npossibly execute arbitrary code. (CVE-2015-8778)\n\nMaksymilian Arciemowicz discovered a stack-based buffer overflow in the\ncatopen function in the GNU C Library when handling long catalog names. An\nattacker could use this to cause a denial of service (application crash) or\npossibly execute arbitrary code. (CVE-2015-8779)\n\nFlorian Weimer discovered that the getnetbyname implementation in the GNU C\nLibrary did not properly handle long names passed as arguments. An attacker\ncould use to cause a denial of service (stack exhaustion leading to an\napplication crash). (CVE-2016-3075)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.14","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.14"},{"name":"libc6-dev","version":"2.15-0ubuntu10.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.14"}],"trusty":[{"name":"eglibc","version":"2.19-0ubuntu6.8","description":"GNU C Library","is_source":true},{"name":"eglibc-source","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"glibc-doc","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc-bin","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc-dev-bin","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-amd64","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-armel","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-dev","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-dev-armel","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-dev-i386","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-dev-x32","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-i386","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-pic","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-ppc64","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-prof","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-udeb","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libc6-x32","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libnss-dns-udeb","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"libnss-files-udeb","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"multiarch-support","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"},{"name":"nscd","version":"2.19-0ubuntu6.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8","pocket":"security"}],"wily":[{"name":"glibc","version":"2.21-0ubuntu4.2","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.21-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.21-0ubuntu4.2"},{"name":"libc6-dev","version":"2.21-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.21-0ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2013-2207","CVE-2014-8121","CVE-2014-9761","CVE-2015-1781","CVE-2015-5277","CVE-2015-8776","CVE-2015-8777","CVE-2015-8778","CVE-2015-8779","CVE-2016-2856","CVE-2016-3075"]}]},{"id":"CVE-2013-1881","published":"2013-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files\nvia an XML document containing an external entity declaration in\nconjunction with an entity reference, related to an XML External Entity\n(XXE) issue.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fixing this also requires a change to gtk+ in raring and earlier"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2149-2","https://ubuntu.com/security/notices/USN-2149-1","https://www.cve.org/CVERecord?id=CVE-2013-1881"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=924414","https://bugzilla.redhat.com/show_bug.cgi?id=1061085 (regression)","https://bugzilla.gnome.org/show_bug.cgi?id=691708","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=724741"],"patches":{"librsvg":["upstream: https://git.gnome.org/browse/librsvg/commit/?id=d83e426fff3f6d0fa6042d0930fb70357db24125","upstream: https://git.gnome.org/browse/librsvg/commit/?id=f01aded72c38f0e18bc7ff67dee800e380251c8e","upstream: https://git.gnome.org/browse/gtk+/commit/?id=86ecf54139874e5e2eee8bfd55b93e28f969bf72","upstream: https://git.gnome.org/browse/gtk+/commit/?id=7b4f82ccc6c180b809cd3b7b6582394ce741a14e","upstream: https://git.gnome.org/browse/gtk+/commit/?id=3d602f5b0a67a7b515dc5add504e02e486aad70c"]},"tags":{},"packages":[{"name":"librsvg","source":"https://ubuntu.com/security/cve?package=librsvg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=librsvg","debian":"https://tracker.debian.org/pkg/librsvg","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.36.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.36.3-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.36.4-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.40.0-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-2149-1","USN-2149-2"],"notices":[{"id":"USN-2149-1","title":"librsvg vulnerability","summary":"Librsvg could be made to expose sensitive information.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2014-03-17T11:48:48.324015","description":"It was discovered that librsvg would load XML external entities by default.\nIf a user were tricked into viewing a specially crafted SVG file, an\nattacker could possibly obtain access to arbitrary files.\n","is_hidden":false,"release_packages":{"precise":[{"name":"librsvg","version":"2.36.1-0ubuntu1.1","description":"renderer library for SVG files","is_source":true},{"name":"librsvg2-2","version":"2.36.1-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librsvg","version_link":"https://launchpad.net/ubuntu/+source/librsvg/2.36.1-0ubuntu1.1"}],"saucy":[{"name":"librsvg","version":"2.36.4-2ubuntu0.1","description":"renderer library for SVG files","is_source":true},{"name":"librsvg2-2","version":"2.36.4-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librsvg","version_link":"https://launchpad.net/ubuntu/+source/librsvg/2.36.4-2ubuntu0.1"}],"quantal":[{"name":"librsvg","version":"2.36.3-0ubuntu1.1","description":"renderer library for SVG files","is_source":true},{"name":"librsvg2-2","version":"2.36.3-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/librsvg","version_link":"https://launchpad.net/ubuntu/+source/librsvg/2.36.3-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2013-1881"]},{"id":"USN-2149-2","title":"GTK+ update","summary":"This update provides a compatibility fix for GTK+.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2014-03-17T11:55:03.822246","description":"USN-2149-1 fixed a vulnerability in librsvg. This update provides a\ncompatibility fix for GTK+ to work with the librsvg security update.\n\nOriginal advisory details:\n\n It was discovered that librsvg would load XML external entities by default.\n If a user were tricked into viewing a specially crafted SVG file, an\n attacker could possibly obtain access to arbitrary files.\n","is_hidden":false,"release_packages":{"precise":[{"name":"gtk+3.0","version":"3.4.2-0ubuntu0.7","description":"GTK+ graphical user interface library","is_source":true},{"name":"libgtk-3-0","version":"3.4.2-0ubuntu0.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gtk+3.0","version_link":"https://launchpad.net/ubuntu/+source/gtk+3.0/3.4.2-0ubuntu0.7"}],"quantal":[{"name":"gtk+3.0","version":"3.6.0-0ubuntu3.3","description":"GTK+ graphical user interface library","is_source":true},{"name":"libgtk-3-0","version":"3.6.0-0ubuntu3.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gtk+3.0","version_link":"https://launchpad.net/ubuntu/+source/gtk+3.0/3.6.0-0ubuntu3.3"}]},"type":"USN","cves_ids":["CVE-2013-1881"]}]},{"id":"CVE-2012-4424","published":"2013-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka\nglibc or libc6) 2.17 and earlier allows context-dependent attackers to\ncause a denial of service (crash) or possibly execute arbitrary code via a\nlong string that triggers a malloc failure and use of the alloca function.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"introduced in http://sourceware.org/git/?p=glibc.git;a=commitdiff;h=5358d026c74"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/09/13/16","https://ubuntu.com/security/notices/USN-1991-1","https://www.cve.org/CVERecord?id=CVE-2012-4424"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=689423","http://sourceware.org/bugzilla/show_bug.cgi?id=14552 (dupe)","http://sourceware.org/bugzilla/show_bug.cgi?id=14547"],"patches":{"glibc":[],"eglibc":["upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=1326ba1af22068db9488c2328bdaf852b8a93dcf","upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=141f3a77fe4f1b59b0afa9bf6909cd2000448883"]},"tags":{"glibc":["stack-protector"],"eglibc":["stack-protector"]},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.11.1-0ubuntu7.13","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.15-0ubuntu20.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2.17-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.17-93ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1991-1"],"notices":[{"id":"USN-1991-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-10-21T16:20:34.407898","description":"It was discovered that the GNU C Library incorrectly handled the strcoll()\nfunction. An attacker could use this issue to cause a denial of service, or\npossibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)\n\nIt was discovered that the GNU C Library incorrectly handled multibyte\ncharacters in the regular expression matcher. An attacker could use this\nissue to cause a denial of service. (CVE-2013-0242)\n\nIt was discovered that the GNU C Library incorrectly handled large numbers\nof domain conversion results in the getaddrinfo() function. An attacker\ncould use this issue to cause a denial of service. (CVE-2013-1914)\n\nIt was discovered that the GNU C Library readdir_r() function incorrectly\nhandled crafted NTFS or CIFS images. An attacker could use this issue to\ncause a denial of service, or possibly execute arbitrary code.\n(CVE-2013-4237)\n\nIt was discovered that the GNU C Library incorrectly handled memory\nallocation. An attacker could use this issue to cause a denial of service.\n(CVE-2013-4332)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.5","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.5"}],"lucid":[{"name":"eglibc","version":"2.11.1-0ubuntu7.13","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.11.1-0ubuntu7.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.11.1-0ubuntu7.13"}],"quantal":[{"name":"eglibc","version":"2.15-0ubuntu20.2","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu20.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu20.2"}],"raring":[{"name":"eglibc","version":"2.17-0ubuntu5.1","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.17-0ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.17-0ubuntu5.1"}]},"type":"USN","cves_ids":["CVE-2012-4412","CVE-2012-4424","CVE-2013-0242","CVE-2013-1914","CVE-2013-4237","CVE-2013-4332"]}]},{"id":"CVE-2012-4412","published":"2013-10-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in string/strcoll_l.c in the GNU C Library (aka glibc or\nlibc6) 2.17 and earlier allows context-dependent attackers to cause a\ndenial of service (crash) or possibly execute arbitrary code via a long\nstring, which triggers a heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/09/07/9","https://ubuntu.com/security/notices/USN-1991-1","https://www.cve.org/CVERecord?id=CVE-2012-4412"],"bugs":["http://sourceware.org/bugzilla/show_bug.cgi?id=14547","https://bugzilla.redhat.com/show_bug.cgi?id=855385","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=687530","https://bugs.launchpad.net/ubuntu/+source/eglibc/+bug/1048203"],"patches":{"glibc":[],"eglibc":["upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=1326ba1af22068db9488c2328bdaf852b8a93dcf","upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=303e567a8062200dc06acde7c76fc34679f08d8f"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.11.1-0ubuntu7.13","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.15-0ubuntu10.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.15-0ubuntu20.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2.17-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2.17-93ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1991-1"],"notices":[{"id":"USN-1991-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in the GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-10-21T16:20:34.407898","description":"It was discovered that the GNU C Library incorrectly handled the strcoll()\nfunction. An attacker could use this issue to cause a denial of service, or\npossibly execute arbitrary code. (CVE-2012-4412, CVE-2012-4424)\n\nIt was discovered that the GNU C Library incorrectly handled multibyte\ncharacters in the regular expression matcher. An attacker could use this\nissue to cause a denial of service. (CVE-2013-0242)\n\nIt was discovered that the GNU C Library incorrectly handled large numbers\nof domain conversion results in the getaddrinfo() function. An attacker\ncould use this issue to cause a denial of service. (CVE-2013-1914)\n\nIt was discovered that the GNU C Library readdir_r() function incorrectly\nhandled crafted NTFS or CIFS images. An attacker could use this issue to\ncause a denial of service, or possibly execute arbitrary code.\n(CVE-2013-4237)\n\nIt was discovered that the GNU C Library incorrectly handled memory\nallocation. An attacker could use this issue to cause a denial of service.\n(CVE-2013-4332)\n","is_hidden":false,"release_packages":{"precise":[{"name":"eglibc","version":"2.15-0ubuntu10.5","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu10.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.5"}],"lucid":[{"name":"eglibc","version":"2.11.1-0ubuntu7.13","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.11.1-0ubuntu7.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.11.1-0ubuntu7.13"}],"quantal":[{"name":"eglibc","version":"2.15-0ubuntu20.2","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.15-0ubuntu20.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu20.2"}],"raring":[{"name":"eglibc","version":"2.17-0ubuntu5.1","description":"GNU C Library","is_source":true},{"name":"libc6","version":"2.17-0ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/eglibc","version_link":"https://launchpad.net/ubuntu/+source/eglibc/2.17-0ubuntu5.1"}]},"type":"USN","cves_ids":["CVE-2012-4412","CVE-2012-4424","CVE-2013-0242","CVE-2013-1914","CVE-2013-4237","CVE-2013-4332"]}]},{"id":"CVE-2013-4402","published":"2013-10-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before\n2.0.22 allows remote attackers to cause a denial of service (infinite\nrecursion) via a crafted OpenPGP message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/000334.html","http://lists.gnupg.org/pipermail/gnupg-announce/2013q4/000333.html","https://ubuntu.com/security/notices/USN-1987-1","https://www.cve.org/CVERecord?id=CVE-2013-4402"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725439 (gnupg)","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725433 (gnupg2)"],"patches":{"gnupg":[],"gnupg2":[]},"tags":{},"packages":[{"name":"gnupg","source":"https://ubuntu.com/security/cve?package=gnupg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnupg","debian":"https://tracker.debian.org/pkg/gnupg","statuses":[{"release_codename":"lucid","status":"released","description":"1.4.10-2ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.4.11-3ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.4.11-3ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1.4.12-7ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.15","component":null,"pocket":"security"}]},{"name":"gnupg2","source":"https://ubuntu.com/security/cve?package=gnupg2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnupg2","debian":"https://tracker.debian.org/pkg/gnupg2","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.0.17-2ubuntu2.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.0.17-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2.0.19-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.22","component":null,"pocket":"security"}]}],"notices_ids":["USN-1987-1"],"notices":[{"id":"USN-1987-1","title":"GnuPG vulnerabilities","summary":"Several security issues were fixed in GnuPG.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-10-09T16:37:51.213518","description":"Daniel Kahn Gillmor discovered that GnuPG treated keys with empty usage\nflags as being valid for all usages. (CVE-2013-4351)\n\nTaylor R Campbell discovered that GnuPG incorrectly handled certain OpenPGP\nmessages. If a user or automated system were tricked into processing a\nspecially-crafted message, GnuPG could consume resources, resulting in a\ndenial of service. (CVE-2013-4402)\n","is_hidden":false,"release_packages":{"precise":[{"name":"gnupg2","version":"2.0.17-2ubuntu2.12.04.3","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg","version":"1.4.11-3ubuntu2.4","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg2","version":"2.0.17-2ubuntu2.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg2","version_link":"https://launchpad.net/ubuntu/+source/gnupg2/2.0.17-2ubuntu2.12.04.3"},{"name":"gnupg","version":"1.4.11-3ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg","version_link":"https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu2.4"}],"lucid":[{"name":"gnupg2","version":"2.0.14-1ubuntu1.6","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg","version":"1.4.10-2ubuntu1.4","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg2","version":"2.0.14-1ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg2","version_link":"https://launchpad.net/ubuntu/+source/gnupg2/2.0.14-1ubuntu1.6"},{"name":"gnupg","version":"1.4.10-2ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg","version_link":"https://launchpad.net/ubuntu/+source/gnupg/1.4.10-2ubuntu1.4"}],"quantal":[{"name":"gnupg2","version":"2.0.17-2ubuntu3.2","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg","version":"1.4.11-3ubuntu4.3","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg2","version":"2.0.17-2ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg2","version_link":"https://launchpad.net/ubuntu/+source/gnupg2/2.0.17-2ubuntu3.2"},{"name":"gnupg","version":"1.4.11-3ubuntu4.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg","version_link":"https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu4.3"}],"raring":[{"name":"gnupg2","version":"2.0.19-2ubuntu1.1","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg","version":"1.4.12-7ubuntu1.2","description":"GNU privacy guard - a free PGP replacement","is_source":true},{"name":"gnupg2","version":"2.0.19-2ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg2","version_link":"https://launchpad.net/ubuntu/+source/gnupg2/2.0.19-2ubuntu1.1"},{"name":"gnupg","version":"1.4.12-7ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/gnupg","version_link":"https://launchpad.net/ubuntu/+source/gnupg/1.4.12-7ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2013-4351","CVE-2013-4402"]}]},{"id":"CVE-2013-5915","published":"2013-10-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe RSA-CRT implementation in PolarSSL before 1.2.9 does not properly\nperform Montgomery multiplication, which might allow remote attackers to\nconduct a timing side-channel attack and retrieve RSA private keys.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2013-05","http://secunia.com/advisories/55084","http://osvdb.org/98049","https://www.cve.org/CVERecord?id=CVE-2013-5915"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725359"],"patches":{"polarssl":[],"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.9","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.3.4-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.3.4-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.3.4-1","component":null,"pocket":"security"}]},{"name":"polarssl","source":"https://ubuntu.com/security/cve?package=polarssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=polarssl","debian":"https://tracker.debian.org/pkg/polarssl","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.9","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.3.4-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.3.4-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.3.4-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.3.4-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4788","published":"2013-10-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6)\n2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the\nrandom value for the pointer guard, which makes it easier for\ncontext-dependent attackers to control execution flow by leveraging a\nbuffer-overflow vulnerability in an application and using the known zero\nvalue pointer guard to calculate a pointer address.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"PoC in linux-distros@ (tested on Ubuntu 12.04, 13.04 and Debian 7.1)\nOnly statically compiled executables, dynamic not affected\nupstream patch not available as of 2013-07-12"},{"author":"seth-arnold","note":"PTR MANGLE is a security-hardening feature; exploiting this flaw\nrequires a flaw in a statically linked executable that allows write\naccess to one of the types of pointers that is mangled. Fixing the\nconsequences of this flaw requires rebuilding all security-sensitive\nstatically linked executables."},{"author":"mdeslaur","note":"fix for this was reverted in saucy as it was causing the ARM\ntestuite to fail."},{"author":"sbeattie","note":"fix was re-enabled in trusty with the addition of the\npatches/any/cvs-CVE-2013-4788-static-ptrguard-arm.diff patch."},{"author":"mdeslaur","note":"we will not be fixing this issue for earlier releases."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://hmarco.org/bugs/CVE-2013-4788.html","https://www.cve.org/CVERecord?id=CVE-2013-4788"],"bugs":["http://sourceware.org/bugzilla/show_bug.cgi?id=15754","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=717178","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4788"],"patches":{"eglibc":["other: http://hmarco.org/bugs/patches/ptr_mangle-eglibc-2.17.patch","upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=c61b4d41c9647a54a329aa021341c0eb032b793e","upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=0b1f8e35640f5b3f7af11764ade3ff060211c309","upstream: https://sourceware.org/git/?p=glibc.git;a=commit;h=5ebbff8fd1529aec13ac4d2906c1a36f3e738519"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.18-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":66860,"limit":20,"total_results":79316}