{"cves":[{"id":"CVE-2013-1652","published":"2013-03-12T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPuppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and\nPuppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote\nauthenticated users with a valid certificate and private key to read\narbitrary catalogs or poison the master's cache via unspecified vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Upstream no longer supports 0.25.x as found in lucid. The code\nis substantially different, rendering a backport of this\nsecurity update difficult. Since puppet in Lucid is almost\nend-of-life, we aren't planning on backporting the security fix\nto it. For Lucid users, we recommend using puppet\n2.7.1-1ubuntu3.8~ubuntu10.04.1 currently in lucid-backports."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1759-1","https://www.cve.org/CVERecord?id=CVE-2013-1652"],"bugs":[""],"patches":{"puppet":[]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.7.1-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.7.18-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.18, 2.7.21, 3.1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1759-1"],"notices":[{"id":"USN-1759-1","title":"Puppet vulnerabilities","summary":"Several security issues were fixed in Puppet.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-03-12T19:42:18.308422","description":"It was discovered that Puppet agents incorrectly handled certain kick\nconnections in a non-default configuration. An attacker on an authenticated\nclient could use this issue to possibly execute arbitrary code.\n(CVE-2013-1653)\n\nIt was discovered that Puppet incorrectly handled certain catalog requests.\nAn attacker on an authenticated client could use this issue to possibly\nexecute arbitrary code on the master. (CVE-2013-1640)\n\nIt was discovered that Puppet incorrectly handled certain client requests.\nAn attacker on an authenticated client could use this issue to possibly\nperform unauthorized actions. (CVE-2013-1652)\n\nIt was discovered that Puppet incorrectly handled certain SSL connections.\nAn attacker could use this issue to possibly downgrade connections to\nSSLv2. (CVE-2013-1654)\n\nIt was discovered that Puppet incorrectly handled serialized attributes.\nAn attacker on an authenticated client could use this issue to possibly\ncause a denial of service, or execute arbitrary. (CVE-2013-1655)\n\nIt was discovered that Puppet incorrectly handled submitted reports.\nAn attacker on an authenticated node could use this issue to possibly\nsubmit a report for any other node. (CVE-2013-2275)\n","is_hidden":false,"release_packages":{"precise":[{"name":"puppet","version":"2.7.11-1ubuntu2.2","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.11-1ubuntu2.2"}],"quantal":[{"name":"puppet","version":"2.7.18-1ubuntu1.1","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.18-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.18-1ubuntu1.1"}],"oneiric":[{"name":"puppet","version":"2.7.1-1ubuntu3.8","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.1-1ubuntu3.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.1-1ubuntu3.8"}]},"type":"USN","cves_ids":["CVE-2013-1640","CVE-2013-1652","CVE-2013-1653","CVE-2013-1654","CVE-2013-1655","CVE-2013-2275"]}]},{"id":"CVE-2013-1640","published":"2013-03-12T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) template and (2) inline_template functions in the master server in\nPuppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and\nPuppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote\nauthenticated users to execute arbitrary code via a crafted catalog\nrequest.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Upstream no longer supports 0.25.x as found in lucid. The code\nis substantially different, rendering a backport of this\nsecurity update difficult. Since puppet in Lucid is almost\nend-of-life, we aren't planning on backporting the security fix\nto it. For Lucid users, we recommend using puppet\n2.7.1-1ubuntu3.8~ubuntu10.04.1 currently in lucid-backports."}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://puppetlabs.com/security/cve/cve-2013-1640/","https://ubuntu.com/security/notices/USN-1759-1","https://www.cve.org/CVERecord?id=CVE-2013-1640"],"bugs":[""],"patches":{"puppet":[]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.7.1-1ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.11-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.7.18-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.18, 2.7.21, 3.1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1759-1"],"notices":[{"id":"USN-1759-1","title":"Puppet vulnerabilities","summary":"Several security issues were fixed in Puppet.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-03-12T19:42:18.308422","description":"It was discovered that Puppet agents incorrectly handled certain kick\nconnections in a non-default configuration. An attacker on an authenticated\nclient could use this issue to possibly execute arbitrary code.\n(CVE-2013-1653)\n\nIt was discovered that Puppet incorrectly handled certain catalog requests.\nAn attacker on an authenticated client could use this issue to possibly\nexecute arbitrary code on the master. (CVE-2013-1640)\n\nIt was discovered that Puppet incorrectly handled certain client requests.\nAn attacker on an authenticated client could use this issue to possibly\nperform unauthorized actions. (CVE-2013-1652)\n\nIt was discovered that Puppet incorrectly handled certain SSL connections.\nAn attacker could use this issue to possibly downgrade connections to\nSSLv2. (CVE-2013-1654)\n\nIt was discovered that Puppet incorrectly handled serialized attributes.\nAn attacker on an authenticated client could use this issue to possibly\ncause a denial of service, or execute arbitrary. (CVE-2013-1655)\n\nIt was discovered that Puppet incorrectly handled submitted reports.\nAn attacker on an authenticated node could use this issue to possibly\nsubmit a report for any other node. (CVE-2013-2275)\n","is_hidden":false,"release_packages":{"precise":[{"name":"puppet","version":"2.7.11-1ubuntu2.2","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.11-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.11-1ubuntu2.2"}],"quantal":[{"name":"puppet","version":"2.7.18-1ubuntu1.1","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.18-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.18-1ubuntu1.1"}],"oneiric":[{"name":"puppet","version":"2.7.1-1ubuntu3.8","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.1-1ubuntu3.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.1-1ubuntu3.8"}]},"type":"USN","cves_ids":["CVE-2013-1640","CVE-2013-1652","CVE-2013-1653","CVE-2013-1654","CVE-2013-1655","CVE-2013-2275"]}]},{"id":"CVE-2011-4966","published":"2013-03-12T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmodules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is\nenabled for user authentication, does not properly check the password\nexpiration in /etc/shadow, which allows remote authenticated users to\nauthenticate using an expired password.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-2122-1","https://www.cve.org/CVERecord?id=CVE-2011-4966"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=694407","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4966"],"patches":{"freeradius":["upstream: https://github.com/alandekok/freeradius-server/commit/1b1ec5ce75e224bd1755650c18ccdaa6dc53e605"]},"tags":{},"packages":[{"name":"freeradius","source":"https://ubuntu.com/security/cve?package=freeradius","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freeradius","debian":"https://tracker.debian.org/pkg/freeradius","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.1.8+dfsg-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.1.10+dfsg-3ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.1.12+dfsg-1.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"2.1.12+dfsg-1.2ubuntu5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.12+dfsg-1.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-2122-1"],"notices":[{"id":"USN-2122-1","title":"FreeRADIUS vulnerabilities","summary":"Several security issues were fixed in FreeRADIUS.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2014-02-26T13:07:35.681340","description":"It was discovered that FreeRADIUS incorrectly handled unix authentication.\nA remote user could successfully authenticate with an expired password.\n(CVE-2011-4966)\n\nPierre Carrier discovered that FreeRADIUS incorrectly handled rlm_pap\nhash processing. An authenticated user could use this issue to cause\nFreeRADIUS to crash, resulting in a denial of service, or possibly execute\narbitrary code. The default compiler options for affected releases should\nreduce the vulnerability to a denial of service. (CVE-2014-2015)\n","is_hidden":false,"release_packages":{"precise":[{"name":"freeradius","version":"2.1.10+dfsg-3ubuntu0.12.04.2","description":"a high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.10+dfsg-3ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-3ubuntu0.12.04.2"}],"saucy":[{"name":"freeradius","version":"2.1.12+dfsg-1.2ubuntu5.1","description":"high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.12+dfsg-1.2ubuntu5.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.12+dfsg-1.2ubuntu5.1"}],"lucid":[{"name":"freeradius","version":"2.1.8+dfsg-1ubuntu1.1","description":"a high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.8+dfsg-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.8+dfsg-1ubuntu1.1"}],"quantal":[{"name":"freeradius","version":"2.1.12+dfsg-1.1ubuntu0.1","description":"high-performance and highly configurable RADIUS server","is_source":true},{"name":"freeradius","version":"2.1.12+dfsg-1.1ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/freeradius","version_link":"https://launchpad.net/ubuntu/+source/freeradius/2.1.12+dfsg-1.1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2011-4966","CVE-2014-2015"]}]},{"id":"CVE-2013-2503","published":"2013-03-11T17:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPrivoxy before 3.0.21 does not properly handle Proxy-Authenticate and\nProxy-Authorization headers in the client-server data stream, which makes\nit easier for remote HTTP servers to spoof the intended proxy service via a\n407 (aka Proxy Authentication Required) HTTP status code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.c22.cc/2013/03/11/privoxy-proxy-authentication-credential-exposure-cve-2013-2503/","http://ijbswa.cvs.sourceforge.net/viewvc/ijbswa/current/ChangeLog?revision=1.188&view=markup","https://www.cve.org/CVERecord?id=CVE-2013-2503"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702896"],"patches":{"privoxy":[]},"tags":{},"packages":[{"name":"privoxy","source":"https://ubuntu.com/security/cve?package=privoxy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=privoxy","debian":"https://tracker.debian.org/pkg/privoxy","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.0.21-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.0.21-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.21","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.0.21-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.0.21-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.0.21-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0.21-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.0.21-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.0.21-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2555","published":"2013-03-11T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in Adobe Flash Player before 10.3.183.75 and 11.x before\n11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before\n11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and\nbefore 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe\nAIR SDK & Compiler before 3.7.0.1530 allows remote attackers to execute\narbitrary code via unspecified vectors, as demonstrated by VUPEN during a\nPwn2Own competition at CanSecWest 2013.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"chriscoulson provides updates for partner (adobe-flashplugin)"},{"author":"mdeslaur","note":"possibly windows-only, marking as not-affected for now."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157","http://twitter.com/VUPEN/statuses/309713355466227713","http://twitter.com/thezdi/statuses/309756927301283840","https://www.cve.org/CVERecord?id=CVE-2013-2555"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2550","published":"2013-03-11T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Adobe Reader 11.0.02 allows attackers to\nbypass the sandbox protection mechanism via unknown vectors, as\ndemonstrated by George Hotz during a Pwn2Own competition at CanSecWest\n2013.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157","http://twitter.com/thezdi/statuses/309771882612281344","http://www.adobe.com/support/security/bulletins/apsb13-15.html","https://www.cve.org/CVERecord?id=CVE-2013-2550"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.5.5-1precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.5.5-1quantal1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"9.5.5-1raring1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.5.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2549","published":"2013-03-11T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Adobe Reader 11.0.02 allows remote attackers\nto execute arbitrary code via vectors related to a \"break into the\nsandbox,\" as demonstrated by George Hotz during a Pwn2Own competition at\nCanSecWest 2013.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157","http://twitter.com/thezdi/statuses/309771882612281344","http://www.adobe.com/support/security/bulletins/apsb13-15.html","https://www.cve.org/CVERecord?id=CVE-2013-2549"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.5.5-1precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.5.5-1quantal1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"9.5.5-1raring1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.5.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0912","published":"2013-03-11T10:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nWebKit in Google Chrome before 25.0.1364.160 allows remote attackers to\nexecute arbitrary code via vectors that leverage \"type confusion.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.de/2013/03/stable-channel-update_7.html","http://labs.mwrinfosecurity.com/blog/2013/03/06/pwn2own-at-cansecwest-2013/","https://www.cve.org/CVERecord?id=CVE-2013-0912"],"bugs":["https://bugs.launchpad.net/bugs/1132568"],"patches":{"chromium-browser":[],"webkit":[],"webkitgtk":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"25.0.1364.160-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"25.0.1364.160-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"25.0.1364.160-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"25.0.1364.160-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.0.1364.160","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"25.0.1364.160-0ubuntu1","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1836","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMoodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and\n2.4.x before 2.4.2 does not properly manage privileges for WebDAV\nrepositories, which allows remote authenticated users to read, modify, or\ndelete arbitrary site-wide repositories by leveraging certain read access.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0019"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1836"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37852"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.9.4.dfsg-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2, 2.3.5, 2.2.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1835","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMoodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and\n2.4.x before 2.4.2 allows remote authenticated administrators to obtain\nsensitive information from the external repositories of arbitrary users by\nleveraging the login_as feature.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0018"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1835"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36426"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.9.4.dfsg-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2, 2.3.5, 2.2.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1834","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nnotes/edit.php in Moodle 1.9.x through 1.9.19, 2.x through 2.1.10, 2.2.x\nbefore 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote\nauthenticated users to reassign notes via a modified (1) userid or (2)\ncourseid field.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0017"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1834"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37411"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2, 2.3.5, 2.2.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1833","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in the File Picker\nmodule in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before\n2.3.5, and 2.4.x before 2.4.2 allow remote authenticated users to inject\narbitrary web script or HTML via a crafted filename.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0015"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1833"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37507"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.9.4.dfsg-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2, 2.3.5, 2.2.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1832","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nrepository/webdav/lib.php in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8,\n2.3.x before 2.3.5, and 2.4.x before 2.4.2 includes the WebDAV password in\nthe configuration form, which allows remote authenticated administrators to\nobtain sensitive information by configuring an instance.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0014"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1832"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37681"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.9.4.dfsg-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2, 2.3.5, 2.2.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1831","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before\n2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive\ninformation via an invalid request, which reveals the absolute path in an\nexception message.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0013"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1831"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36901"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2, 2.3.5, 2.2.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1830","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nuser/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before\n2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles\nsetting, which allows remote attackers to obtain sensitive course-profile\ninformation by leveraging the guest role, as demonstrated by a Google\nsearch.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0012"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1830"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37481"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2, 2.3.5, 2.2.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1829","published":"2013-03-11T04:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ncalendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not\nconsider capability requirements before displaying calendar subscriptions,\nwhich allows remote authenticated users to obtain potentially sensitive\ninformation by leveraging the student role.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"MSA-13-0011"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-1829"],"bugs":[""],"patches":{"moodle":["upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37338"]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.9.4.dfsg-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.9.dfsg2-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.9.9.dfsg2-6","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"2.2.3.dfsg-2.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2496","published":"2013-03-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg\nthrough 1.1.3 does not properly determine certain end pointers, which\nallows remote attackers to cause a denial of service (out-of-bounds array\naccess and application crash) or possibly have unspecified other impact via\ncrafted Microsoft RLE data.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ffmpeg-extra in multiverse needs to have matching version\nlibav-extra is built with tarball produced by libav package\nignoring releases near EoL. New version not available from\nupstream."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://git.videolan.org/?p=ffmpeg.git;a=commit;h=e398990eb87785e20e065cd3f14d1dbb69df4392","https://ubuntu.com/security/notices/USN-1790-1","https://www.cve.org/CVERecord?id=CVE-2013-2496"],"bugs":["https://bugs.launchpad.net/bugs/1163354"],"patches":{"ffmpeg":[],"ffmpeg-extra":[],"libav":["upstream: http://git.libav.org/?p=libav.git;a=commit;h=327ff82bac3081d918dceb4931c77e25d0a1480d","upstream: http://git.libav.org/?p=libav.git;a=commit;h=4160398e2a3e229e29dff03300aaf630e726a768"],"libav-extra":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ffmpeg-extra","source":"https://ubuntu.com/security/cve?package=ffmpeg-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg-extra","debian":"https://tracker.debian.org/pkg/ffmpeg-extra","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:0.8.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6:0.8.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"6:0.8.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6","component":null,"pocket":"security"}]},{"name":"libav-extra","source":"https://ubuntu.com/security/cve?package=libav-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav-extra","debian":"https://tracker.debian.org/pkg/libav-extra","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:0.8.6ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6:0.8.6ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"6:0.8.6ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1790-1"],"notices":[{"id":"USN-1790-1","title":"Libav vulnerabilities","summary":"Libav could be made to crash or run programs as your login if it opened a\nspecially crafted file. \n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2013-04-04T14:50:20.115267","description":"It was discovered that Libav incorrectly handled certain malformed media\nfiles. If a user were tricked into opening a crafted media file, an\nattacker could cause a denial of service via application crash, or possibly\nexecute arbitrary code with the privileges of the user invoking the\nprogram.\n","is_hidden":false,"release_packages":{"precise":[{"name":"libav","version":"4:0.8.6-0ubuntu0.12.04.1","description":"Multimedia player, server, encoder and transcoder","is_source":true},{"name":"libavformat53","version":"4:0.8.6-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/4:0.8.6-0ubuntu0.12.04.1"},{"name":"libavcodec53","version":"4:0.8.6-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/4:0.8.6-0ubuntu0.12.04.1"}],"quantal":[{"name":"libav","version":"6:0.8.6-0ubuntu0.12.10.1","description":"Multimedia player, server, encoder and transcoder","is_source":true},{"name":"libavformat53","version":"6:0.8.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/6:0.8.6-0ubuntu0.12.10.1"},{"name":"libavcodec53","version":"6:0.8.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/6:0.8.6-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0894","CVE-2013-2277","CVE-2013-2495","CVE-2013-2496"]}]},{"id":"CVE-2013-2495","published":"2013-03-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe iff_read_header function in iff.c in libavformat in FFmpeg through\n1.1.3 does not properly handle data sizes for Interchange File Format (IFF)\ndata during operations involving a CMAP chunk or a video codec, which\nallows remote attackers to cause a denial of service (integer overflow,\nout-of-bounds array access, and application crash) or possibly have\nunspecified other impact via a crafted header.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ffmpeg-extra in multiverse needs to have matching version\nlibav-extra is built with tarball produced by libav package\nignoring releases near EoL. New version not available from\nupstream."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://git.videolan.org/?p=ffmpeg.git;a=commit;h=3dbc0ff9c3e6f6e0d08ea3d42cb33761bae084ba","https://ubuntu.com/security/notices/USN-1790-1","https://www.cve.org/CVERecord?id=CVE-2013-2495"],"bugs":["https://bugs.launchpad.net/bugs/1163354"],"patches":{"ffmpeg":[],"ffmpeg-extra":[],"libav":["upstream: http://git.libav.org/?p=libav.git;a=commit;h=36aad4f1cc707feb15f071260a99f239b6623a59"],"libav-extra":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ffmpeg-extra","source":"https://ubuntu.com/security/cve?package=ffmpeg-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg-extra","debian":"https://tracker.debian.org/pkg/ffmpeg-extra","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:0.8.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6:0.8.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"6:0.8.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6","component":null,"pocket":"security"}]},{"name":"libav-extra","source":"https://ubuntu.com/security/cve?package=libav-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav-extra","debian":"https://tracker.debian.org/pkg/libav-extra","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:0.8.6ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6:0.8.6ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"6:0.8.6ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1790-1"],"notices":[{"id":"USN-1790-1","title":"Libav vulnerabilities","summary":"Libav could be made to crash or run programs as your login if it opened a\nspecially crafted file. \n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2013-04-04T14:50:20.115267","description":"It was discovered that Libav incorrectly handled certain malformed media\nfiles. If a user were tricked into opening a crafted media file, an\nattacker could cause a denial of service via application crash, or possibly\nexecute arbitrary code with the privileges of the user invoking the\nprogram.\n","is_hidden":false,"release_packages":{"precise":[{"name":"libav","version":"4:0.8.6-0ubuntu0.12.04.1","description":"Multimedia player, server, encoder and transcoder","is_source":true},{"name":"libavformat53","version":"4:0.8.6-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/4:0.8.6-0ubuntu0.12.04.1"},{"name":"libavcodec53","version":"4:0.8.6-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/4:0.8.6-0ubuntu0.12.04.1"}],"quantal":[{"name":"libav","version":"6:0.8.6-0ubuntu0.12.10.1","description":"Multimedia player, server, encoder and transcoder","is_source":true},{"name":"libavformat53","version":"6:0.8.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/6:0.8.6-0ubuntu0.12.10.1"},{"name":"libavcodec53","version":"6:0.8.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/6:0.8.6-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0894","CVE-2013-2277","CVE-2013-2495","CVE-2013-2496"]}]},{"id":"CVE-2011-2504","published":"2013-03-08T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in x11perfcomp in XFree86 x11perf\nbefore 1.5.4 allows local users to gain privileges via unspecified Trojan\nhorse code in the current working directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2013-0502.html","https://www.cve.org/CVERecord?id=CVE-2011-2504"],"bugs":[""],"patches":{"x11-apps":[]},"tags":{},"packages":[{"name":"x11-apps","source":"https://ubuntu.com/security/cve?package=x11-apps","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=x11-apps","debian":"https://tracker.debian.org/pkg/x11-apps","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"7.7~2ubuntu1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.7~1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0308","published":"2013-03-08T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe imap-send command in GIT before 1.8.1.4 does not verify that the server\nhostname matches a domain name in the subject's Common Name (CN) or\nsubjectAltName field of the X.509 certificate, which allows\nman-in-the-middle attackers to spoof SSL servers via an arbitrary valid\ncertificate.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Debian and Ubuntu's git does not enable SSL"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=git&m=136134619013145&w=2","https://www.cve.org/CVERecord?id=CVE-2013-0308"],"bugs":[""],"patches":{"git-core":[],"git":[]},"tags":{},"packages":[{"name":"git","source":"https://ubuntu.com/security/cve?package=git","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=git","debian":"https://tracker.debian.org/pkg/git","statuses":[{"release_codename":"hardy","status":"not-affected","description":"not the same software","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"git-core","source":"https://ubuntu.com/security/cve?package=git-core","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=git-core","debian":"https://tracker.debian.org/pkg/git-core","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":67860,"limit":20,"total_results":79316}