{"cves":[{"id":"CVE-2012-4735","published":"2013-07-24T12:01:00","updated_at":"2025-08-04T19:24:16.829397+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs:\nCVE-2012-6578, CVE-2012-6579, CVE-2012-6580, CVE-2012-6581.  Reason: This\ncandidate is a duplicate of CVE-2012-6578, CVE-2012-6579, CVE-2012-6580,\nand CVE-2012-6581.  Notes: All CVE users should reference one or more of\nCVE-2012-6578, CVE-2012-6579, CVE-2012-6580, and CVE-2012-6581 instead of\nthis candidate.  All references and descriptions in this candidate have\nbeen removed to prevent accidental usage","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.debian.org/security/2012/dsa-2567","https://www.cve.org/CVERecord?id=CVE-2012-4735"],"bugs":[""],"patches":{"request-tracker4":[],"request-tracker3.8":[]},"tags":{},"packages":[{"name":"request-tracker3.8","source":"https://ubuntu.com/security/cve?package=request-tracker3.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=request-tracker3.8","debian":"https://tracker.debian.org/pkg/request-tracker3.8","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8.8-7+squeeze6","component":null,"pocket":"security"}]},{"name":"request-tracker4","source":"https://ubuntu.com/security/cve?package=request-tracker4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=request-tracker4","debian":"https://tracker.debian.org/pkg/request-tracker4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2249","published":"2013-07-23T17:20:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server\nbefore 2.4.5 proceeds with save operations for a session without\nconsidering the dirty flag and the requirement for a new session ID, which\nhas unspecified impact and remote attack vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 2.4.x"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.apache.org/dist/httpd/CHANGES_2.4.6","https://www.cve.org/CVERecord?id=CVE-2013-2249"],"bugs":[""],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/session/mod_session_dbd.c?r1=1409170&r2=1488158&diff_format=h"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2165","published":"2013-07-23T11:03:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in\nRed Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform\nthrough 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0\nCP10 and 5.x through 5.2.0, Red Hat JBoss BRMS through 5.3.1, Red Hat JBoss\nSOA Platform through 4.3.0 CP05 and 5.x through 5.3.1, Red Hat JBoss Portal\nthrough 4.3 CP07 and 5.x through 5.2.2, and Red Hat JBoss Operations\nNetwork through 2.4.2 and 3.x through 3.1.2 does not restrict the classes\nfor which deserialization methods can be called, which allows remote\nattackers to execute arbitrary code via crafted serialized data.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per Debian, not affected, only builds a few libraries, not the\nfull application server, #581226"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2013-1041.html","https://www.cve.org/CVERecord?id=CVE-2013-2165"],"bugs":[""],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4160","published":"2013-07-22T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nLittle CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other\nproducts, allows remote attackers to cause a denial of service (NULL\npointer dereference and crash) via vectors related to (1)\ncmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3)\ncmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"OpenJDK issue 8007925 does not affect lcms (code not present)\nOpenJDK issue 8007926 does not affect lcms (code not present)\nOpenJDK issue 8007927 does not affect lcms (code not present)\nOpenJDK issue 8007929 does not affect lcms (code not present)\nOpenJDK issue 8009654 does not affect lcms (code not present)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://github.com/mm2/Little-CMS/commit/91c2db7f2559be504211b283bc3a2c631d6f06d9","https://bugzilla.novell.com/show_bug.cgi?id=826097#c9","http://www.openwall.com/lists/oss-security/2013/07/22","https://ubuntu.com/security/notices/USN-1911-1","https://ubuntu.com/security/notices/USN-1911-2","https://www.cve.org/CVERecord?id=CVE-2013-4160"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=714529"],"patches":{"lcms2":[],"lcms":[],"ghostscript":[]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"9.07~dfsg2-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lcms","source":"https://ubuntu.com/security/cve?package=lcms","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lcms","debian":"https://tracker.debian.org/pkg/lcms","statuses":[{"release_codename":"lucid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lcms2","source":"https://ubuntu.com/security/cve?package=lcms2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lcms2","debian":"https://tracker.debian.org/pkg/lcms2","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.2+git20110628-2ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.2+git20110628-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2.4-0ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-1911-1","USN-1911-2"],"notices":[{"id":"USN-1911-1","title":"Little CMS vulnerability","summary":"Little CMS could be made to crash if it opened a specially crafted file.\n","instructions":"After a standard system update you need to restart any applications that\nuses Little CMS to make all the necessary changes.\n","references":[],"published":"2013-07-29T17:55:47.240047","description":"It was discovered that Little CMS did not properly verify certain memory\nallocations. If a user or automated system using Little CMS were tricked\ninto opening a specially crafted file, an attacker could cause Little CMS\nto crash.\n","is_hidden":false,"release_packages":{"precise":[{"name":"lcms2","version":"2.2+git20110628-2ubuntu3.1","description":"Little CMS 2 color management library","is_source":true},{"name":"liblcms2-2","version":"2.2+git20110628-2ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/lcms2","version_link":"https://launchpad.net/ubuntu/+source/lcms2/2.2+git20110628-2ubuntu3.1"}],"quantal":[{"name":"lcms2","version":"2.2+git20110628-2ubuntu4.1","description":"Little CMS 2 color management library","is_source":true},{"name":"liblcms2-2","version":"2.2+git20110628-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/lcms2","version_link":"https://launchpad.net/ubuntu/+source/lcms2/2.2+git20110628-2ubuntu4.1"}],"raring":[{"name":"lcms2","version":"2.4-0ubuntu3.1","description":"Little CMS 2 color management library","is_source":true},{"name":"liblcms2-2","version":"2.4-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/lcms2","version_link":"https://launchpad.net/ubuntu/+source/lcms2/2.4-0ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2013-4160"]},{"id":"USN-1911-2","title":"Ghostscript vulnerability","summary":"Ghostscript could be made to crash if it opened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-07-31T20:09:48.877217","description":"USN-1911-1 fixed vulnerabilities in Little CMS. This update provides the\ncorresponding updates for Ghostscript.\n\nOriginal advisory details:\n\n It was discovered that Little CMS did not properly verify certain memory\n allocations. If a user or automated system using Little CMS were tricked\n into opening a specially crafted file, an attacker could cause Little CMS\n to crash.\n","is_hidden":false,"release_packages":{"raring":[{"name":"ghostscript","version":"9.07~dfsg2-0ubuntu3.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"libgs9","version":"9.07~dfsg2-0ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.07~dfsg2-0ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2013-4160"]}]},{"id":"CVE-2013-2251","published":"2013-07-20T03:37:00","updated_at":"2025-08-25T20:51:34.141977+00:00","description":"\nApache Struts 2.0.0 through 2.3.15 allows remote attackers to execute\narbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)\nredirect:, or (3) redirectAction: prefix.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Only affected Struts 2\nThe bulk of the patch appears to be in\nhttp://svn.apache.org/viewvc?view=revision&revision=1502979\nI've reviewed libstruts1.2-java code and could not find analogous code\nin our codebase."}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://struts.apache.org/release/2.3.x/docs/s2-016.html","https://www.cve.org/CVERecord?id=CVE-2013-2251","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2070","published":"2013-07-20T03:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nhttp/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0\nthrough 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows\nremote attackers to cause a denial of service (crash) and obtain sensitive\ninformation from worker process memory via a crafted proxy response, a\nsimilar vulnerability to CVE-2013-2028.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"per upstream 1.1.4 and higher"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/05/13/3","https://www.cve.org/CVERecord?id=CVE-2013-2070"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=708164","https://launchpad.net/bugs/1182586"],"patches":{"nginx":["other: http://nginx.org/download/patch.2013.proxy.txt"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"lucid","status":"not-affected","description":"0.7.65-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.1.19-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.2.1-2.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1.2.6-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2028","published":"2013-07-20T03:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9\nthrough 1.4.0 allows remote attackers to cause a denial of service (crash)\nand execute arbitrary code via a chunked Transfer-Encoding request with a\nlarge chunk size, which triggers an integer signedness error and a\nstack-based buffer overflow.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream says \"The problem affects nginx 1.3.9 - 1.4.0.\"\ncode doesn't seem present in version 1.2.x in the archive"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://mailman.nginx.org/pipermail/nginx-announce/2013/000112.html","https://www.cve.org/CVERecord?id=CVE-2013-2028"],"bugs":[""],"patches":{"nginx":["upstream: http://nginx.org/download/patch.2013.chunked.txt"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.1,1.5.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1879","published":"2013-07-20T03:37:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in scheduled.jsp in Apache\nActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web\nscript or HTML via vectors involving the \"cron of a message.\"","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"patch in subversion 1459265"},{"author":"mdeslaur","note":"scheduler not shipped in Debian/Ubuntu"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1879"],"bugs":["https://issues.apache.org/jira/browse/AMQ-4397"],"patches":{"activemq":[]},"tags":{},"packages":[{"name":"activemq","source":"https://ubuntu.com/security/cve?package=activemq","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=activemq","debian":"https://tracker.debian.org/pkg/activemq","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [code not present]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-3414","published":"2013-07-19T14:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload\n2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image\nManager 1.1, and other products, allows remote attackers to inject\narbitrary web script or HTML via the movieName parameter, related to the\n\"ExternalInterface.call\" function.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://code.google.com/p/swfupload/issues/detail?id=376","https://www.cve.org/CVERecord?id=CVE-2012-3414"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681323","https://bugs.launchpad.net/bugs/1026766"],"patches":{"libjs-swfupload":[]},"tags":{},"packages":[{"name":"libjs-swfupload","source":"https://ubuntu.com/security/cve?package=libjs-swfupload","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libjs-swfupload","debian":"https://tracker.debian.org/pkg/libjs-swfupload","statuses":[{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.0.1+ds1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4122","published":"2013-07-18T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL\nvalue is returned upon an error by the crypt function as implemented in\nglibc 2.17 and later, which allows remote attackers to cause a denial of\nservice (thread crash and consumption) via (1) an invalid salt or, when\nFIPS-140 is enabled, a (2) DES or (3) MD5 encrypted password, which\ntriggers a NULL pointer dereference.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"NULL return from crypt() if the salt isn't sane\nUpgraded to medium, bug report shows remote attackers can disable\nthe sasl service by repeating the attack; THREADS=0 configuration is a\nwork-around that may help to prevent abuse."},{"author":"mdeslaur","note":"eglibc only returns NULL from crypt() in 2.17+, so quantal\nand older are not affected.\n2015-09-25: patch was dropped by mistake in debian's\n2.1.26 package, fixed again in 2.1.26.dfsg1-14"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://openwall.com/lists/oss-security/2013/07/12/3","http://git.cyrusimap.org/cyrus-sasl/commit/?id=dedad73e5e7a75d01a5f3d5a6702ab8ccd2ff40d","https://ubuntu.com/security/notices/USN-1988-1","https://ubuntu.com/security/notices/USN-2755-1","https://www.cve.org/CVERecord?id=CVE-2013-4122"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=716835","https://bugs.launchpad.net/ubuntu/+source/cyrus-sasl2/+bug/1187001"],"patches":{"cyrus-sasl2":["upstream: http://git.cyrusimap.org/cyrus-sasl/commit/?id=dedad73e5e7a75d01a5f3d5a6702ab8ccd2ff40d","other: http://sourceforge.net/projects/miscellaneouspa/files/glibc217/cyrus-sasl-2.1.23-glibc217-crypt.diff","other: http://sourceforge.net/projects/miscellaneouspa/files/glibc217/cyrus-sasl-2.1.26-glibc217-crypt.diff"]},"tags":{},"packages":[{"name":"cyrus-sasl2","source":"https://ubuntu.com/security/cve?package=cyrus-sasl2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cyrus-sasl2","debian":"https://tracker.debian.org/pkg/cyrus-sasl2","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2.1.25.dfsg1-6ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.1.25.dfsg1-17","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.26.dfsg1-14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"2.1.26.dfsg1-13ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1988-1","USN-2755-1"],"notices":[{"id":"USN-1988-1","title":"Cyrus SASL vulnerability","summary":"Cyrus SASL could be made to crash if it processed specially crafted input.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2013-10-09T16:44:33.726164","description":"It was discovered that Cyrus SASL incorrectly handled certain invalid\npassword salts. An attacker could use this issue to cause Cyrus SASL to\ncrash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"raring":[{"name":"cyrus-sasl2","version":"2.1.25.dfsg1-6ubuntu0.1","description":"Cyrus Simple Authentication and Security Layer","is_source":true},{"name":"libsasl2-2","version":"2.1.25.dfsg1-6ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cyrus-sasl2","version_link":"https://launchpad.net/ubuntu/+source/cyrus-sasl2/2.1.25.dfsg1-6ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2013-4122"]},{"id":"USN-2755-1","title":"Cyrus SASL vulnerability","summary":"Cyrus SASL could be made to crash if it processed specially crafted input.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2015-09-30T16:53:30.420378","description":"It was discovered that Cyrus SASL incorrectly handled certain invalid\npassword salts. An attacker could use this issue to cause Cyrus SASL to\ncrash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"vivid":[{"name":"cyrus-sasl2","version":"2.1.26.dfsg1-13ubuntu0.1","description":"Cyrus Simple Authentication and Security Layer","is_source":true},{"name":"libsasl2-2","version":"2.1.26.dfsg1-13ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/cyrus-sasl2","version_link":"https://launchpad.net/ubuntu/+source/cyrus-sasl2/2.1.26.dfsg1-13ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2013-4122"]}]},{"id":"CVE-2013-3811","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to InnoDB, a different vulnerability than\nCVE-2013-3806.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3811"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3810","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to XA Transactions.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3810"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3808","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote\nauthenticated users to affect availability via unknown vectors related to\nServer Options.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3808"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.31-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.31-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"5.5.31-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.31","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"released","description":"5.1.69-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.69","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3807","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote attackers to affect confidentiality and\nintegrity via unknown vectors related to Server Privileges.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3807"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3806","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to InnoDB, a different vulnerability than\nCVE-2013-3811.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3806"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3805","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect\navailability via unknown vectors related to Prepared Statements.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3805"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.31-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.31-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"5.5.31-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.31","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3801","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect\navailability via unknown vectors related to Server Options.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3801"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"5.5.31-0ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"5.5.31-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"5.5.31-0ubuntu0.13.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.31","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3798","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote attackers to affect integrity and\navailability via unknown vectors related to MemCached.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3798"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3796","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to Server Optimizer.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3796"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-3795","published":"2013-07-17T13:41:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the MySQL Server component in Oracle MySQL\n5.6.11 and earlier allows remote authenticated users to affect availability\nvia unknown vectors related to Data Manipulation Language.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"mysql-cluster-7.0 not supported per Ubuntu Server team"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html","https://www.cve.org/CVERecord?id=CVE-2013-3795"],"bugs":[""],"patches":{"mysql-dfsg-5.1":[],"mysql-5.5":[],"mysql-cluster-7.0":[]},"tags":{},"packages":[{"name":"mysql-5.5","source":"https://ubuntu.com/security/cve?package=mysql-5.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-5.5","debian":"https://tracker.debian.org/pkg/mysql-5.5","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-cluster-7.0","source":"https://ubuntu.com/security/cve?package=mysql-cluster-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-cluster-7.0","debian":"https://tracker.debian.org/pkg/mysql-cluster-7.0","statuses":[{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"mysql-dfsg-5.1","source":"https://ubuntu.com/security/cve?package=mysql-dfsg-5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mysql-dfsg-5.1","debian":"https://tracker.debian.org/pkg/mysql-dfsg-5.1","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":67220,"limit":20,"total_results":79316}