{"cves":[{"id":"CVE-2013-1902","published":"2013-04-04T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13,\n8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary\nfiles with predictable filenames, which has unspecified impact and attack\nvectors related to \"graphical installers for Linux and Mac OS X.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"we don't use the installer in Ubuntu"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1902"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/1163184"],"patches":{"postgresql-9.1":[],"postgresql-8.4":[],"postgresql-8.3":[],"postgresql-8.2":[]},"tags":{},"packages":[{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.17","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.1.9","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1901","published":"2013-04-04T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly\ncheck REPLICATION privileges, which allows remote authenticated users to\nbypass intended backup restrictions by calling the (1) pg_start_backup or\n(2) pg_stop_backup functions.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"looks to be 9.0+ only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1789-1","https://www.cve.org/CVERecord?id=CVE-2013-1901"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/1163184"],"patches":{"postgresql-9.1":[],"postgresql-8.4":[],"postgresql-8.3":[],"postgresql-8.2":[]},"tags":{},"packages":[{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.17","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"9.1.9-0ubuntu11.10","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.1.9-0ubuntu12.04","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.1.9-0ubuntu12.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.1.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-1789-1"],"notices":[{"id":"USN-1789-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2013-04-04T13:48:52.242494","description":"Mitsumasa Kondo and Kyotaro Horiguchi discovered that PostgreSQL\nincorrectly handled certain connection requests containing database names\nstarting with a dash. A remote attacker could use this flaw to damage or\ndestroy files within a server's data directory. This issue only applied to\nUbuntu 11.10, Ubuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-1899)\n\nMarko Kreen discovered that PostgreSQL incorrectly generated random\nnumbers. An authenticated attacker could use this flaw to possibly guess\nanother database user's random numbers. (CVE-2013-1900)\n\nNoah Misch discovered that PostgreSQL incorrectly handled certain privilege\nchecks. An unprivileged attacker could use this flaw to possibly interfere\nwith in-progress backups. This issue only applied to Ubuntu 11.10,\nUbuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-1901)\n","is_hidden":false,"release_packages":{"precise":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu12.04"}],"hardy":[{"name":"postgresql-8.3","version":"8.3.23-0ubuntu8.04.1","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.3","version":"8.3.23-0ubuntu8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.23-0ubuntu8.04.1"}],"lucid":[{"name":"postgresql-8.4","version":"8.4.17-0ubuntu10.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.17-0ubuntu10.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.17-0ubuntu10.04"}],"quantal":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu12.10"}],"oneiric":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu11.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu11.10"}]},"type":"USN","cves_ids":["CVE-2013-1899","CVE-2013-1900","CVE-2013-1901"]}]},{"id":"CVE-2013-1900","published":"2013-04-04T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and\n8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random\nnumbers, which might allow remote authenticated users to have an\nunspecified impact via vectors related to the \"contrib/pgcrypto functions.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.postgresql.org/about/news/1456/","https://ubuntu.com/security/notices/USN-1789-1","https://www.cve.org/CVERecord?id=CVE-2013-1900"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/1163184"],"patches":{"postgresql-9.1":[],"postgresql-8.4":[],"postgresql-8.3":[],"postgresql-8.2":[]},"tags":{},"packages":[{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"hardy","status":"released","description":"8.3.23-0ubuntu8.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.4.17-0ubuntu10.04","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8.4.17-0ubuntu12.04","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.17","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"9.1.9-0ubuntu11.10","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.1.9-0ubuntu12.04","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.1.9-0ubuntu12.10","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"9.1.9-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.1.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-1789-1"],"notices":[{"id":"USN-1789-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2013-04-04T13:48:52.242494","description":"Mitsumasa Kondo and Kyotaro Horiguchi discovered that PostgreSQL\nincorrectly handled certain connection requests containing database names\nstarting with a dash. A remote attacker could use this flaw to damage or\ndestroy files within a server's data directory. This issue only applied to\nUbuntu 11.10, Ubuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-1899)\n\nMarko Kreen discovered that PostgreSQL incorrectly generated random\nnumbers. An authenticated attacker could use this flaw to possibly guess\nanother database user's random numbers. (CVE-2013-1900)\n\nNoah Misch discovered that PostgreSQL incorrectly handled certain privilege\nchecks. An unprivileged attacker could use this flaw to possibly interfere\nwith in-progress backups. This issue only applied to Ubuntu 11.10,\nUbuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-1901)\n","is_hidden":false,"release_packages":{"precise":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu12.04"}],"hardy":[{"name":"postgresql-8.3","version":"8.3.23-0ubuntu8.04.1","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.3","version":"8.3.23-0ubuntu8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.23-0ubuntu8.04.1"}],"lucid":[{"name":"postgresql-8.4","version":"8.4.17-0ubuntu10.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.17-0ubuntu10.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.17-0ubuntu10.04"}],"quantal":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu12.10"}],"oneiric":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu11.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu11.10"}]},"type":"USN","cves_ids":["CVE-2013-1899","CVE-2013-1900","CVE-2013-1901"]}]},{"id":"CVE-2013-1899","published":"2013-04-04T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nArgument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x\nbefore 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a\ndenial of service (file corruption), and allows remote authenticated users\nto modify configuration settings and execute arbitrary code, via a\nconnection request using a database name that begins with a \"-\" (hyphen).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"looks like it's 9.0+ only"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.postgresql.org/about/news/1456/","https://ubuntu.com/security/notices/USN-1789-1","https://www.cve.org/CVERecord?id=CVE-2013-1899"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/1163184"],"patches":{"postgresql-9.1":[],"postgresql-8.4":[],"postgresql-8.3":[],"postgresql-8.2":[]},"tags":{},"packages":[{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.17","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"9.1.9-0ubuntu11.10","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.1.9-0ubuntu12.04","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.1.9-0ubuntu12.10","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.1.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-1789-1"],"notices":[{"id":"USN-1789-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2013-04-04T13:48:52.242494","description":"Mitsumasa Kondo and Kyotaro Horiguchi discovered that PostgreSQL\nincorrectly handled certain connection requests containing database names\nstarting with a dash. A remote attacker could use this flaw to damage or\ndestroy files within a server's data directory. This issue only applied to\nUbuntu 11.10, Ubuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-1899)\n\nMarko Kreen discovered that PostgreSQL incorrectly generated random\nnumbers. An authenticated attacker could use this flaw to possibly guess\nanother database user's random numbers. (CVE-2013-1900)\n\nNoah Misch discovered that PostgreSQL incorrectly handled certain privilege\nchecks. An unprivileged attacker could use this flaw to possibly interfere\nwith in-progress backups. This issue only applied to Ubuntu 11.10,\nUbuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-1901)\n","is_hidden":false,"release_packages":{"precise":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu12.04"}],"hardy":[{"name":"postgresql-8.3","version":"8.3.23-0ubuntu8.04.1","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.3","version":"8.3.23-0ubuntu8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.23-0ubuntu8.04.1"}],"lucid":[{"name":"postgresql-8.4","version":"8.4.17-0ubuntu10.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.17-0ubuntu10.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.17-0ubuntu10.04"}],"quantal":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu12.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu12.10"}],"oneiric":[{"name":"postgresql-9.1","version":"9.1.9-0ubuntu11.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.9-0ubuntu11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.9-0ubuntu11.10"}]},"type":"USN","cves_ids":["CVE-2013-1899","CVE-2013-1900","CVE-2013-1901"]}]},{"id":"CVE-2013-0799","published":"2013-04-03T11:56:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the Mozilla Maintenance Service in Mozilla Firefox\nbefore 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and\nThunderbird ESR 17.x before 17.0.5 on Windows allows local users to gain\nprivileges via crafted arguments.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Affects the Mozilla Maintenance Service on Windows only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-32.html","https://www.cve.org/CVERecord?id=CVE-2013-0799"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0798","published":"2013-04-03T11:56:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 20.0 on Android uses world-writable and\nworld-readable permissions for the app_tmp installation directory in the\nlocal filesystem, which allows attackers to modify add-ons before\ninstallation via an application that leverages the time window during which\napp_tmp is used.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Affects Firefox for Android only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-33.html","https://www.cve.org/CVERecord?id=CVE-2013-0798"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0797","published":"2013-04-03T11:56:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in the Mozilla Updater in Mozilla\nFirefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before\n17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17\nallows local users to gain privileges via a Trojan horse DLL file in an\nunspecified directory.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"xulrunner-1.9.2 unmaintained upstream (see README.mozilla for\ndetails)"},{"author":"chrisccoulson","note":"Only affects builds with Mozilla's updater enabled"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-34.html","https://www.cve.org/CVERecord?id=CVE-2013-0797"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0790","published":"2013-04-03T11:56:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the browser engine in Mozilla Firefox before\n20.0 on Android allows remote attackers to cause a denial of service (stack\nmemory corruption and application crash) or possibly execute arbitrary code\nvia unknown vectors involving a plug-in.","ubuntu_description":"","notes":[{"author":"chrisccoulson","note":"Affects Firefox for Android only"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-30.html","https://www.cve.org/CVERecord?id=CVE-2013-0790"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0800","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger signedness error in the pixman_fill_sse2 function in pixman-sse2.c\nin Pixman, as distributed with Cairo and used in Mozilla Firefox before\n20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5,\nThunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other\nproducts, allows remote attackers to execute arbitrary code via crafted\nvalues that trigger attempted use of a (1) negative box boundary or (2)\nnegative box size, leading to an out-of-bounds write operation.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"xulrunner-1.9.2 unmaintained upstream (see README.mozilla for\ndetails)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-31.html","https://ubuntu.com/security/notices/USN-1786-1","https://ubuntu.com/security/notices/USN-1791-1","https://www.cve.org/CVERecord?id=CVE-2013-0800"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.5+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.5+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"17.0.5+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"17.0.5+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1","USN-1791-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]},{"id":"USN-1791-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1162043"],"published":"2013-04-08T12:50:47.916669","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic and Joe Drew discovered multiple memory safety issues affecting\nThunderbird. If the user were tricked into opening a specially crafted\nmessage with scripting enabled, an attacker could possibly exploit these\nto cause a denial of service via application crash, or potentially\nexecute code with the privileges of the user invoking Thunderbird.\n(CVE-2013-0788)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks if scripting were enabled. (CVE-2013-0793)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. If a user had enabled scripting, an attacker\ncould potentially exploit this to steal confidential data or execute code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Thunderbird. An attacker\ncould potentially exploit this to execute code with the privileges of\nthe user invoking Thunderbird if scripting were enabled. This issue only\naffects users with Intel graphics drivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.10.04.1"}],"quantal":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.10.1"}],"oneiric":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0791","CVE-2013-0793","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0796","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe WebGL subsystem in Mozilla Firefox before 20.0, Firefox ESR 17.x before\n17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and\nSeaMonkey before 2.17 on Linux does not properly interact with Mesa\ndrivers, which allows remote attackers to execute arbitrary code or cause a\ndenial of service (free of unallocated memory) via unspecified vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"xulrunner-1.9.2 unmaintained upstream (see README.mozilla for\ndetails)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-35.html","https://ubuntu.com/security/notices/USN-1786-1","https://ubuntu.com/security/notices/USN-1791-1","https://www.cve.org/CVERecord?id=CVE-2013-0796"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.5+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.5+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"17.0.5+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"17.0.5+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1","USN-1791-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]},{"id":"USN-1791-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1162043"],"published":"2013-04-08T12:50:47.916669","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic and Joe Drew discovered multiple memory safety issues affecting\nThunderbird. If the user were tricked into opening a specially crafted\nmessage with scripting enabled, an attacker could possibly exploit these\nto cause a denial of service via application crash, or potentially\nexecute code with the privileges of the user invoking Thunderbird.\n(CVE-2013-0788)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks if scripting were enabled. (CVE-2013-0793)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. If a user had enabled scripting, an attacker\ncould potentially exploit this to steal confidential data or execute code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Thunderbird. An attacker\ncould potentially exploit this to execute code with the privileges of\nthe user invoking Thunderbird if scripting were enabled. This issue only\naffects users with Intel graphics drivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.10.04.1"}],"quantal":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.10.1"}],"oneiric":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0791","CVE-2013-0793","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0795","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe System Only Wrapper (SOW) implementation in Mozilla Firefox before\n20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5,\nThunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 does not\nprevent use of the cloneNode method for cloning a protected node, which\nallows remote attackers to bypass the Same Origin Policy or possibly\nexecute arbitrary JavaScript code with chrome privileges via a crafted web\nsite.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"xulrunner-1.9.2 unmaintained upstream (see README.mozilla for\ndetails)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-36.html","https://ubuntu.com/security/notices/USN-1786-1","https://ubuntu.com/security/notices/USN-1791-1","https://www.cve.org/CVERecord?id=CVE-2013-0795"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.5+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.5+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"17.0.5+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"17.0.5+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1","USN-1791-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]},{"id":"USN-1791-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1162043"],"published":"2013-04-08T12:50:47.916669","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic and Joe Drew discovered multiple memory safety issues affecting\nThunderbird. If the user were tricked into opening a specially crafted\nmessage with scripting enabled, an attacker could possibly exploit these\nto cause a denial of service via application crash, or potentially\nexecute code with the privileges of the user invoking Thunderbird.\n(CVE-2013-0788)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks if scripting were enabled. (CVE-2013-0793)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. If a user had enabled scripting, an attacker\ncould potentially exploit this to steal confidential data or execute code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Thunderbird. An attacker\ncould potentially exploit this to execute code with the privileges of\nthe user invoking Thunderbird if scripting were enabled. This issue only\naffects users with Intel graphics drivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.10.04.1"}],"quantal":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.10.1"}],"oneiric":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0791","CVE-2013-0793","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0794","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin\nspoofing of tab-modal dialogs, which allows remote attackers to conduct\nphishing attacks via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-37.html","https://ubuntu.com/security/notices/USN-1786-1","https://www.cve.org/CVERecord?id=CVE-2013-0794"],"bugs":[""],"patches":{"firefox":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0793","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird\nbefore 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before\n2.17 do not ensure the correctness of the address bar during history\nnavigation, which allows remote attackers to conduct cross-site scripting\n(XSS) attacks or phishing attacks by leveraging control over navigation\ntiming.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"xulrunner-1.9.2 unmaintained upstream (see README.mozilla for\ndetails)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-38.html","https://ubuntu.com/security/notices/USN-1786-1","https://ubuntu.com/security/notices/USN-1791-1","https://www.cve.org/CVERecord?id=CVE-2013-0793"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.5+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.5+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"17.0.5+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"17.0.5+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1","USN-1791-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]},{"id":"USN-1791-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1162043"],"published":"2013-04-08T12:50:47.916669","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic and Joe Drew discovered multiple memory safety issues affecting\nThunderbird. If the user were tricked into opening a specially crafted\nmessage with scripting enabled, an attacker could possibly exploit these\nto cause a denial of service via application crash, or potentially\nexecute code with the privileges of the user invoking Thunderbird.\n(CVE-2013-0788)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks if scripting were enabled. (CVE-2013-0793)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. If a user had enabled scripting, an attacker\ncould potentially exploit this to steal confidential data or execute code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Thunderbird. An attacker\ncould potentially exploit this to execute code with the privileges of\nthe user invoking Thunderbird if scripting were enabled. This issue only\naffects users with Intel graphics drivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.10.04.1"}],"quantal":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.10.1"}],"oneiric":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0791","CVE-2013-0793","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0792","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 20.0 and SeaMonkey before 2.17, when\ngfx.color_management.enablev4 is used, do not properly handle color\nprofiles during PNG rendering, which allows remote attackers to obtain\nsensitive information from process memory or cause a denial of service\n(memory corruption) via a grayscale PNG image.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-39.html","https://ubuntu.com/security/notices/USN-1786-1","https://www.cve.org/CVERecord?id=CVE-2013-0792"],"bugs":[""],"patches":{"firefox":[],"seamonkey":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0791","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe CERT_DecodeCertPackage function in Mozilla Network Security Services\n(NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before\n17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5,\nSeaMonkey before 2.17, and other products, allows remote attackers to cause\na denial of service (out-of-bounds read and memory corruption) via a\ncrafted certificate.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"xulrunner-1.9.2 unmaintained upstream (see README.mozilla for\ndetails)"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-40.html","https://ubuntu.com/security/notices/USN-1763-1","https://ubuntu.com/security/notices/USN-1786-1","https://ubuntu.com/security/notices/USN-1791-1","https://www.cve.org/CVERecord?id=CVE-2013-0791"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[],"nss":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"nss","source":"https://ubuntu.com/security/cve?package=nss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nss","debian":"https://tracker.debian.org/pkg/nss","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.14.3-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.14.3-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.14.3-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.14.3-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"2:3.14.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"2:3.14.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.14.2","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.5+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.5+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"17.0.5+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"17.0.5+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1","USN-1791-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]},{"id":"USN-1791-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1162043"],"published":"2013-04-08T12:50:47.916669","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic and Joe Drew discovered multiple memory safety issues affecting\nThunderbird. If the user were tricked into opening a specially crafted\nmessage with scripting enabled, an attacker could possibly exploit these\nto cause a denial of service via application crash, or potentially\nexecute code with the privileges of the user invoking Thunderbird.\n(CVE-2013-0788)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks if scripting were enabled. (CVE-2013-0793)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. If a user had enabled scripting, an attacker\ncould potentially exploit this to steal confidential data or execute code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Thunderbird. An attacker\ncould potentially exploit this to execute code with the privileges of\nthe user invoking Thunderbird if scripting were enabled. This issue only\naffects users with Intel graphics drivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.10.04.1"}],"quantal":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.10.1"}],"oneiric":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0791","CVE-2013-0793","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0789","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to\ncause a denial of service (memory corruption and application crash) or\npossibly execute arbitrary code via vectors related to the\nnsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-30.html","https://ubuntu.com/security/notices/USN-1786-1","https://www.cve.org/CVERecord?id=CVE-2013-0789"],"bugs":[""],"patches":{"firefox":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0788","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple unspecified vulnerabilities in the browser engine in Mozilla\nFirefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before\n17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 allow\nremote attackers to cause a denial of service (memory corruption and\napplication crash) or possibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"xulrunner-1.9.2 unmaintained upstream (see README.mozilla for\ndetails)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2013/mfsa2013-30.html","https://ubuntu.com/security/notices/USN-1786-1","https://ubuntu.com/security/notices/USN-1791-1","https://www.cve.org/CVERecord?id=CVE-2013-0788"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"20.0+build1-0ubuntu0.10.04.3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"20.0+build1-0ubuntu0.11.10.3","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"20.0+build1-0ubuntu0.12.04.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"20.0+build1-0ubuntu0.12.10.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"20.0+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20.0","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"2.17","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.5+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.5+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"17.0.5+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"17.0.5+build1-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"17.0.5+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.5","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1786-1","USN-1791-1"],"notices":[{"id":"USN-1786-1","title":"Firefox vulnerabilities","summary":"Firefox could be made to crash or run programs as your login if it\nopened a malicious website.\n","instructions":"After a standard system update you need to restart Firefox to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1161422"],"published":"2013-04-04T14:16:14.951375","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and\nMats Palmgren discovered multiple memory safety issues affecting Firefox.\nIf the user were tricked into opening a specially crafted page, an\nattacker could possibly exploit these to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Firefox. (CVE-2013-0788, CVE-2013-0789)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nTobias Schula discovered an information leak in Firefox when the\ngfx.color_management.enablev4 preference is enabled. If the user were\ntricked into opening a specially crafted image, an attacker could\npotentially exploit this to steal confidential data. By default, the\ngfx.color_management.enablev4 preference is not enabled in Ubuntu.\n(CVE-2013-0792)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks. (CVE-2013-0793)\n\nIt was discovered that the origin indication on tab-modal dialog boxes\ncould be removed, which could allow an attacker's dialog to be displayed\nover another sites content. An attacker could exploit this to conduct\nphishing attacks. (CVE-2013-0794)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. An attacker could potentially exploit this to\nsteal confidential data or execute code with the privileges of the user\ninvoking Firefox. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Firefox. An attacker could\npotentially exploit this to execute code with the privileges of the user\ninvoking Firefox. This issue only affects users with Intel graphics\ndrivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Firefox. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.04.3"}],"lucid":[{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.10.04.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.10.04.3"}],"quantal":[{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.12.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.12.10.3"}],"oneiric":[{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"20.0+build1-0ubuntu0.11.10.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/20.0+build1-0ubuntu0.11.10.3"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0789","CVE-2013-0791","CVE-2013-0792","CVE-2013-0793","CVE-2013-0794","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]},{"id":"USN-1791-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/1162043"],"published":"2013-04-08T12:50:47.916669","description":"Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan\nSreckovic and Joe Drew discovered multiple memory safety issues affecting\nThunderbird. If the user were tricked into opening a specially crafted\nmessage with scripting enabled, an attacker could possibly exploit these\nto cause a denial of service via application crash, or potentially\nexecute code with the privileges of the user invoking Thunderbird.\n(CVE-2013-0788)\n\nAmbroz Bizjak discovered an out-of-bounds array read in the\nCERT_DecodeCertPackage function of the Network Security Services (NSS)\nlibary when decoding certain certificates. An attacker could potentially\nexploit this to cause a denial of service via application crash.\n(CVE-2013-0791)\n\nMariusz Mlynski discovered that timed history navigations could be used to\nload arbitrary websites with the wrong URL displayed in the addressbar. An\nattacker could exploit this to conduct cross-site scripting (XSS) or\nphishing attacks if scripting were enabled. (CVE-2013-0793)\n\nCody Crews discovered that the cloneNode method could be used to\nbypass System Only Wrappers (SOW) to clone a protected node and bypass\nsame-origin policy checks. If a user had enabled scripting, an attacker\ncould potentially exploit this to steal confidential data or execute code\nwith the privileges of the user invoking Thunderbird. (CVE-2013-0795)\n\nA crash in WebGL rendering was discovered in Thunderbird. An attacker\ncould potentially exploit this to execute code with the privileges of\nthe user invoking Thunderbird if scripting were enabled. This issue only\naffects users with Intel graphics drivers. (CVE-2013-0796)\n\nAbhishek Arya discovered an out-of-bounds write in the Cairo graphics\nlibrary. An attacker could potentially exploit this to execute code with\nthe privileges of the user invoking Thunderbird. (CVE-2013-0800)\n","is_hidden":false,"release_packages":{"precise":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.04.1"}],"lucid":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.10.04.1"}],"quantal":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.12.10.1"}],"oneiric":[{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"17.0.5+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/17.0.5+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0788","CVE-2013-0791","CVE-2013-0793","CVE-2013-0795","CVE-2013-0796","CVE-2013-0800"]}]},{"id":"CVE-2013-0131","published":"2013-04-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the NVIDIA GPU driver before 304.88, 310.x before\n310.44, and 313.x before 313.30 for the X Window System on UNIX, when\nNoScanout mode is enabled, allows remote authenticated users to execute\narbitrary code via a large ARGB cursor.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream advisory says vulnerability is present since 195.22\nfixed in 304.88, 310.44, 313.30\nWe aren't going to fix the experimental drivers. Users of the\nexperimental drivers for who this issue is important are\nrecommended to switch to production drivers.\nDoesn't actually affected nvidia-settings and\nnvidia-settings-updates. Updates are simply required for\ncompatibility reasons."},{"author":"jdstrand","note":"no updates from NVIDIA for 195.36 (Ubuntu 10.04 LTS), 280.13 and\n295.20 (Ubuntu 11.10) as of 2013-04-19"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://nvidia.custhelp.com/app/answers/detail/a_id/3290","https://ubuntu.com/security/notices/USN-1799-1","https://www.cve.org/CVERecord?id=CVE-2013-0131"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=704547"],"patches":{"nvidia-graphics-drivers":[],"nvidia-graphics-drivers-304":[],"nvidia-graphics-drivers-304-updates":[],"nvidia-graphics-drivers-310":[],"nvidia-graphics-drivers-310-updates":[],"nvidia-graphics-drivers-313-updates":[],"nvidia-graphics-drivers-experimental-304":[],"nvidia-graphics-drivers-experimental-310":[],"nvidia-graphics-drivers-updates":[],"nvidia-settings":[],"nvidia-settings-updates":[]},"tags":{},"packages":[{"name":"nvidia-graphics-drivers","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"304.88-0ubuntu0.0.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"304.88-0ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"304.88-1","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-304","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-304","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-304","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-304","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"304.88-0ubuntu0.0.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"304.88-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"304.88","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-304-updates","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-304-updates","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-304-updates","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-304-updates","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"304.88-0ubuntu0.0.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"304.88-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"304.88","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-310","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-310","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-310","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-310","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"310.44-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"310.44","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-310-updates","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-310-updates","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-310-updates","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-310-updates","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"310.44-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"310.44","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-313-updates","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-313-updates","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-313-updates","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-313-updates","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"313.30-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"313.30","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-experimental-304","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-experimental-304","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-experimental-304","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-experimental-304","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"304.88","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-experimental-310","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-experimental-310","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-experimental-310","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-experimental-310","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"310.44","component":null,"pocket":"security"}]},{"name":"nvidia-graphics-drivers-updates","source":"https://ubuntu.com/security/cve?package=nvidia-graphics-drivers-updates","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-graphics-drivers-updates","debian":"https://tracker.debian.org/pkg/nvidia-graphics-drivers-updates","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"304.88-0ubuntu0.0.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"304.88-0ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"304.88","component":null,"pocket":"security"}]},{"name":"nvidia-settings","source":"https://ubuntu.com/security/cve?package=nvidia-settings","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-settings","debian":"https://tracker.debian.org/pkg/nvidia-settings","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"nvidia-settings-updates","source":"https://ubuntu.com/security/cve?package=nvidia-settings-updates","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nvidia-settings-updates","debian":"https://tracker.debian.org/pkg/nvidia-settings-updates","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1799-1"],"notices":[{"id":"USN-1799-1","title":"NVIDIA graphics drivers vulnerability","summary":"NVIDIA graphics drivers could be made to run programs as an administrator.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2013-04-10T12:43:19.087684","description":"It was discovered that the NVIDIA graphics drivers incorrectly handled\nlarge ARGB cursors. A local attacker could use this issue to gain root\nprivileges.\n\nThe NVIDIA graphics drivers have been updated to 304.88 to fix this issue.\nIn addition to the security fix, the updated packages contain bug fixes,\nnew features, and possibly incompatible changes.\n","is_hidden":false,"release_packages":{"precise":[{"name":"nvidia-graphics-drivers-updates","version":"304.88-0ubuntu0.0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-settings","version":"304.88-0ubuntu0.0.2","description":"Tool for configuring the NVIDIA graphics driver","is_source":true},{"name":"nvidia-settings-updates","version":"304.88-0ubuntu0.0.2","description":"Tool for configuring the NVIDIA graphics driver","is_source":true},{"name":"nvidia-graphics-drivers","version":"304.88-0ubuntu0.0.2","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-settings","version":"304.88-0ubuntu0.0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-settings","version_link":"https://launchpad.net/ubuntu/+source/nvidia-settings/304.88-0ubuntu0.0.2"},{"name":"nvidia-settings-updates","version":"304.88-0ubuntu0.0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-settings","version_link":"https://launchpad.net/ubuntu/+source/nvidia-settings/304.88-0ubuntu0.0.2"},{"name":"nvidia-current-updates","version":"304.88-0ubuntu0.0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-updates","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-updates/304.88-0ubuntu0.0.1"},{"name":"nvidia-current","version":"304.88-0ubuntu0.0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-settings","version_link":"https://launchpad.net/ubuntu/+source/nvidia-settings/304.88-0ubuntu0.0.2"}],"quantal":[{"name":"nvidia-graphics-drivers-updates","version":"304.88-0ubuntu0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-settings","version":"304.88-0ubuntu0.2","description":"Tool for configuring the NVIDIA graphics driver","is_source":true},{"name":"nvidia-settings-updates","version":"304.88-0ubuntu0.2","description":"Tool for configuring the NVIDIA graphics driver","is_source":true},{"name":"nvidia-graphics-drivers","version":"304.88-0ubuntu0.1","description":"NVIDIA binary Xorg driver","is_source":true},{"name":"nvidia-settings","version":"304.88-0ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-settings","version_link":"https://launchpad.net/ubuntu/+source/nvidia-settings/304.88-0ubuntu0.2"},{"name":"nvidia-settings-updates","version":"304.88-0ubuntu0.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-settings","version_link":"https://launchpad.net/ubuntu/+source/nvidia-settings/304.88-0ubuntu0.2"},{"name":"nvidia-current-updates","version":"304.88-0ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-updates","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-updates/304.88-0ubuntu0.1"},{"name":"nvidia-current","version":"304.88-0ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-updates","version_link":"https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-updates/304.88-0ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2013-0131"]}]},{"id":"CVE-2013-2686","published":"2013-04-01T16:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmain/http.c in the HTTP server in Asterisk Open Source 1.8.x before\n1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk\n1.8.15 before 1.8.15-cert2; and Asterisk Digiumphones 10.x-digiumphones\nbefore 10.12.2-digiumphones does not properly restrict Content-Length\nvalues, which allows remote attackers to conduct stack-consumption attacks\nand cause a denial of service (daemon crash) via a crafted HTTP POST\nrequest. NOTE: this vulnerability exists because of an incorrect fix for\nCVE-2012-5976.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"This is due to an incorrect fix for CVE-2012-5976"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://issues.asterisk.org/jira/browse/ASTERISK-20967","http://downloads.asterisk.org/pub/security/AST-2013-002.html","https://www.cve.org/CVERecord?id=CVE-2013-2686"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=704114"],"patches":{"asterisk":["upstream: http://downloads.asterisk.org/pub/security/AST-2013-002-1.8.diff"]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.19.1, 1.8.20.0, 1.8.20.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2685","published":"2013-04-01T16:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in res/res_format_attr_h264.c in Asterisk Open\nSource 11.x before 11.2.2 allows remote attackers to execute arbitrary code\nvia a long sprop-parameter-sets H.264 media attribute in a SIP Session\nDescription Protocol (SDP) header.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://issues.asterisk.org/jira/browse/ASTERISK-20901","http://downloads.asterisk.org/pub/security/AST-2013-001.html","https://www.cve.org/CVERecord?id=CVE-2013-2685"],"bugs":[""],"patches":{"asterisk":["upstream: Http://downloads.asterisk.org/pub/security/AST-2013-001-11.diff"]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"hardy","status":"not-affected","description":"1:1.4.17~dfsg-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1:1.6.2.5-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1:1.8.4.4~dfsg-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1:1.8.10.1~dfsg-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1:1.8.13.1~dfsg-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":67740,"limit":20,"total_results":79316}