{"cves":[{"id":"CVE-2013-0504","published":"2013-02-27T00:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the broker service in Adobe Flash Player before\n10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and\nbefore 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows attackers\nto execute arbitrary code via unspecified vectors.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"chriscoulson provides updates for partner (adobe-flashplugin)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.adobe.com/support/security/bulletins/apsb13-08.html","https://www.cve.org/CVERecord?id=CVE-2013-0504"],"bugs":[""],"patches":{"flashplugin-nonfree":[],"adobe-flashplugin":[]},"tags":{},"packages":[{"name":"adobe-flashplugin","source":"https://ubuntu.com/security/cve?package=adobe-flashplugin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=adobe-flashplugin","debian":"https://tracker.debian.org/pkg/adobe-flashplugin","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"11.2.202.273-0lucid1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"11.2.202.273-0oneiric1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.273-0precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.273-0quantal1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.273","component":null,"pocket":"security"}]},{"name":"flashplugin-nonfree","source":"https://ubuntu.com/security/cve?package=flashplugin-nonfree","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=flashplugin-nonfree","debian":"https://tracker.debian.org/pkg/flashplugin-nonfree","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"11.2.202.273ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"11.2.202.273ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.2.202.273ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"11.2.202.273ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.2.202.273","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2277","published":"2013-02-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in\nFFmpeg before 1.1.3 does not validate the relationship between luma depth\nand chroma depth, which allows remote attackers to cause a denial of\nservice (out-of-bounds array access and application crash) or possibly have\nunspecified other impact via crafted H.264 data.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"ffmpeg-extra in multiverse needs to have matching version\nlibav-extra is built with tarball produced by libav package"},{"author":"jdstrand","note":"ffmpeg on 10.04 LTS has no error checking of sps->bit_depth_luma\nor sps->bit_depth_chroma (see libavcodec/h264.c line 7140 (after applying\nquilt patches))\nlibav has no error checking of sps->bit_depth_luma os"},{"author":"sps-","note":"bit_depth_chroma (see libavcodec/h264_ps.c, line 338 on 11.10, line 348\non 12.04 LTS and higher)"},{"author":"mdeslaur","note":"ignoring releases near EoL. New version not available from\nupstream."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1790-1","https://www.cve.org/CVERecord?id=CVE-2013-2277"],"bugs":["https://bugs.launchpad.net/bugs/1163354"],"patches":{"ffmpeg":["upstream: http://git.videolan.org/?p=ffmpeg.git;a=commit;h=bdeb61ccc67911cfc5e20c7cfb1312d0501ca90a"],"ffmpeg-extra":[],"libav":["upstream: http://git.libav.org/?p=libav.git;a=commit;h=9e48d77158dcb104fb35b90593ace0b248bda7e1"],"libav-extra":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ffmpeg-extra","source":"https://ubuntu.com/security/cve?package=ffmpeg-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg-extra","debian":"https://tracker.debian.org/pkg/ffmpeg-extra","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:0.8.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6:0.8.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"6:0.8.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav-extra","source":"https://ubuntu.com/security/cve?package=libav-extra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav-extra","debian":"https://tracker.debian.org/pkg/libav-extra","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"4:0.8.6ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6:0.8.6ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"6:0.8.6ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1790-1"],"notices":[{"id":"USN-1790-1","title":"Libav vulnerabilities","summary":"Libav could be made to crash or run programs as your login if it opened a\nspecially crafted file. \n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2013-04-04T14:50:20.115267","description":"It was discovered that Libav incorrectly handled certain malformed media\nfiles. If a user were tricked into opening a crafted media file, an\nattacker could cause a denial of service via application crash, or possibly\nexecute arbitrary code with the privileges of the user invoking the\nprogram.\n","is_hidden":false,"release_packages":{"precise":[{"name":"libav","version":"4:0.8.6-0ubuntu0.12.04.1","description":"Multimedia player, server, encoder and transcoder","is_source":true},{"name":"libavformat53","version":"4:0.8.6-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/4:0.8.6-0ubuntu0.12.04.1"},{"name":"libavcodec53","version":"4:0.8.6-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/4:0.8.6-0ubuntu0.12.04.1"}],"quantal":[{"name":"libav","version":"6:0.8.6-0ubuntu0.12.10.1","description":"Multimedia player, server, encoder and transcoder","is_source":true},{"name":"libavformat53","version":"6:0.8.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/6:0.8.6-0ubuntu0.12.10.1"},{"name":"libavcodec53","version":"6:0.8.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libav","version_link":"https://launchpad.net/ubuntu/+source/libav/6:0.8.6-0ubuntu0.12.10.1"}]},"type":"USN","cves_ids":["CVE-2013-0894","CVE-2013-2277","CVE-2013-2495","CVE-2013-2496"]}]},{"id":"CVE-2013-1775","published":"2013-02-27T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local\nusers or physically proximate attackers to bypass intended time\nrestrictions and retain privileges without re-authenticating by setting the\nsystem clock and sudo user timestamp to the epoch.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/02/27/22","https://ubuntu.com/security/notices/USN-1754-1","https://www.cve.org/CVERecord?id=CVE-2013-1775"],"bugs":[""],"patches":{"sudo":["upstream: http://www.sudo.ws/repos/sudo/rev/ddf399e3e306","upstream: http://www.sudo.ws/repos/sudo/rev/ebd6cc75020f"]},"tags":{},"packages":[{"name":"sudo","source":"https://ubuntu.com/security/cve?package=sudo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sudo","debian":"https://tracker.debian.org/pkg/sudo","statuses":[{"release_codename":"hardy","status":"released","description":"1.6.9p10-1ubuntu3.10","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.7.2p1-1ubuntu5.6","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.7.4p6-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.10p7, 1.8.6p7","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"1.8.3p1-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.8.5p2-1ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1754-1"],"notices":[{"id":"USN-1754-1","title":"Sudo vulnerability","summary":"Sudo could be made to run programs as the administrator without a password\nprompt.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-02-28T13:00:11.318458","description":"Marco Schoepl discovered that Sudo incorrectly handled time stamp files\nwhen the system clock is set to epoch. A local attacker could use this\nissue to run Sudo commands without a password prompt.\n","is_hidden":false,"release_packages":{"precise":[{"name":"sudo","version":"1.8.3p1-1ubuntu3.4","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo-ldap","version":"1.8.3p1-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.3p1-1ubuntu3.4"},{"name":"sudo","version":"1.8.3p1-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.3p1-1ubuntu3.4"}],"hardy":[{"name":"sudo","version":"1.6.9p10-1ubuntu3.10","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo-ldap","version":"1.6.9p10-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.6.9p10-1ubuntu3.10"},{"name":"sudo","version":"1.6.9p10-1ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.6.9p10-1ubuntu3.10"}],"lucid":[{"name":"sudo","version":"1.7.2p1-1ubuntu5.6","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo-ldap","version":"1.7.2p1-1ubuntu5.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.2p1-1ubuntu5.6"},{"name":"sudo","version":"1.7.2p1-1ubuntu5.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.2p1-1ubuntu5.6"}],"quantal":[{"name":"sudo","version":"1.8.5p2-1ubuntu1.1","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo-ldap","version":"1.8.5p2-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.5p2-1ubuntu1.1"},{"name":"sudo","version":"1.8.5p2-1ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.5p2-1ubuntu1.1"}],"oneiric":[{"name":"sudo","version":"1.7.4p6-1ubuntu2.2","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo-ldap","version":"1.7.4p6-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.4p6-1ubuntu2.2"},{"name":"sudo","version":"1.7.4p6-1ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.4p6-1ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2013-1775"]}]},{"id":"CVE-2013-1773","published":"2013-02-26T00:00:00","updated_at":"2026-07-04T07:37:19.799016+00:00","description":"\nBuffer overflow in the VFAT filesystem implementation in the Linux kernel\nbefore 3.3 allows local users to gain privileges or cause a denial of\nservice (system crash) via a VFAT write operation on a filesystem with the\nutf8 mount option, which is not properly handled during UTF-8 to UTF-16\nconversion.","ubuntu_description":"\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/02/26/5","http://www.exploit-db.com/exploits/23248/","https://ubuntu.com/security/notices/USN-1756-1","https://ubuntu.com/security/notices/USN-1760-1","https://ubuntu.com/security/notices/USN-1775-1","https://ubuntu.com/security/notices/USN-1776-1","https://ubuntu.com/security/notices/USN-1778-1","https://www.cve.org/CVERecord?id=CVE-2013-1773"],"bugs":["https://launchpad.net/bugs/1134523"],"patches":{"linux":["break-fix: 74675a58507e769beee7d949dbed788af3c4139d 0720a06a7518c9d0c0125bd5d1f3b6264c55c3dd"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-oneiric":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-46.105","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-32.50","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-22.35","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.5.0-1600.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-351.62","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.10","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.18","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.3]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.9]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-32.50~lucid1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.5.0-18.29~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-5.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-6.37","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-3.21]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-7.32","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-4.19]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1222.36","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1412.15","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1776-1","USN-1756-1","USN-1760-1","USN-1775-1","USN-1778-1"],"notices":[{"id":"USN-1776-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-22T23:24:21.834072","description":"A flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernels handling of memory ranges with\nPROT_NONE when transparent hugepages are in use. An unprivileged local user\ncould exploit this flaw to cause a denial of service (crash the system).\n(CVE-2013-0309)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-351.62","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-351-ec2","version":"2.6.32-351.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-351.62"}]},"type":"USN","cves_ids":["CVE-2013-1773","CVE-2013-0268","CVE-2013-0309"]},{"id":"USN-1756-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-06T10:14:04.085387","description":"A failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-32.50","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-32-powerpc64-smp","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-omap","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-generic","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-server","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-powerpc-smp","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-virtual","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-powerpc","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-generic-pae","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"}]},"type":"USN","cves_ids":["CVE-2013-0216","CVE-2013-0217","CVE-2013-0228","CVE-2013-0268","CVE-2013-0311","CVE-2013-0349","CVE-2013-1773"]},{"id":"USN-1760-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-12T21:03:09.477555","description":"A failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-32.50~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-32-generic","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"},{"name":"linux-image-3.0.0-32-server","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"},{"name":"linux-image-3.0.0-32-generic-pae","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"},{"name":"linux-image-3.0.0-32-virtual","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"}]},"type":"USN","cves_ids":["CVE-2013-0216","CVE-2013-0217","CVE-2013-0228","CVE-2013-0268","CVE-2013-0311","CVE-2013-0349","CVE-2013-1773"]},{"id":"USN-1775-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-22T23:16:34.783221","description":"A flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernels handling of memory ranges with\nPROT_NONE when transparent hugepages are in use. An unprivileged local user\ncould exploit this flaw to cause a denial of service (crash the system).\n(CVE-2013-0309)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-46.105","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-46-sparc64","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-generic","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-virtual","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-powerpc","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-generic-pae","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-powerpc64-smp","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-preempt","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-server","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-lpia","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-ia64","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-versatile","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-powerpc-smp","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-386","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"},{"name":"linux-image-2.6.32-46-sparc64-smp","version":"2.6.32-46.105","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.105"}]},"type":"USN","cves_ids":["CVE-2013-0268","CVE-2013-0309","CVE-2013-1773"]},{"id":"USN-1778-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-22T23:36:07.501620","description":"Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux-ti-omap4","version":"3.0.0-1222.36","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.0.0-1222-omap4","version":"3.0.0-1222.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.0.0-1222.36"}]},"type":"USN","cves_ids":["CVE-2013-0228","CVE-2013-0268","CVE-2013-0311","CVE-2013-0349","CVE-2013-1773"]}]},{"id":"CVE-2013-0349","published":"2013-02-26T00:00:00","updated_at":"2026-07-04T07:32:59.792963+00:00","description":"\nThe hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux\nkernel before 3.7.6 does not properly copy a certain name field, which\nallows local users to obtain sensitive information from kernel memory by\nsetting a long name and making an HIDPCONNADD ioctl call.","ubuntu_description":"\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel.","notes":[{"author":"jdstrand","note":"verified 8.04 LTS - 13.04 is not configured witn HCONFIG_BT=y/m (but\nthey are with CONFIG_BT_HIDP=y/m). All kernel configs need to be verified."},{"author":"jj","note":"there is NO HCONFING_BT, it is CONFIG_BT\nO,P,Q,R:\nCONFIG_BT=m\nCONFIG_BT_HIDP=m\nluicd:\nCONFIG_BT=m/y on all arch except: armel and sparc\nCONFIG_BT_HIDP=m\nhardy:\nCONFIG_BT=m/y on all except: sparc, hppa, i38.virtual xen openvz\nCONFIG_BT_HIDP=m"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1756-1","https://ubuntu.com/security/notices/USN-1760-1","https://ubuntu.com/security/notices/USN-1767-1","https://ubuntu.com/security/notices/USN-1768-1","https://ubuntu.com/security/notices/USN-1769-1","https://ubuntu.com/security/notices/USN-1778-1","https://ubuntu.com/security/notices/USN-1781-1","https://ubuntu.com/security/notices/USN-1774-1","https://ubuntu.com/security/notices/USN-1805-1","https://ubuntu.com/security/notices/USN-1808-1","https://www.cve.org/CVERecord?id=CVE-2013-0349"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=914298","https://launchpad.net/bugs/1134503"],"patches":{"linux":["break-fix: - 0a9ab9bdb3e891762553f667066190c1d22ad62b"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-oneiric":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-46.108","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-32.50","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-39.62","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-26.42","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.8.0-4.8","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1615.23","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-1611.17","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-351.64","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-4.20","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-32.50~lucid1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.5.0-26.42~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.8.0-19.30~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-7.32","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-5.22]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1222.36","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.2.0-1427.36","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.5.0-221.31","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.5.0-221.30","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8~rc6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1767-1","USN-1781-1","USN-1769-1","USN-1774-1","USN-1756-1","USN-1768-1","USN-1760-1","USN-1805-1","USN-1808-1","USN-1778-1"],"notices":[{"id":"USN-1767-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-18T21:43:31.963712","description":"\nAndrew Cooper of Citrix reported a Xen stack corruption in the Linux\nkernel. An unprivileged user in a 32bit PVOPS guest can cause the guest\nkernel to crash, or operate erroneously. (CVE-2013-0190)\n\nA failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was discovered in the Linux kernel Xen PCI backend driver. If a PCI\ndevice is assigned to the guest OS, the guest OS could exploit this flaw to\ncause a denial of service on the host. (CVE-2013-0231)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nA flaw was discovered in the Extended Verification Module (EVM) of the\nLinux kernel. An unprivileged local user code exploit this flaw to cause a\ndenial of service (system crash). (CVE-2013-0313)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA buffer overflow was discovered in the Linux kernel's /dev/kmesg device. A\nlocal user could exploit this flaw to cause a denial of service (system\ncrash). (CVE-2013-1772)\n\nA flaw was discovered in the Edgeort USB serial converter driver when the\ndevice is disconnected while it is in use. A local user could exploit this\nflaw to cause a denial of service (system crash). (CVE-2013-1774)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux","version":"3.2.0-39.62","description":"Linux kernel","is_source":true},{"name":"linux-image-3.2.0-39-generic-pae","version":"3.2.0-39.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-39.62"},{"name":"linux-image-3.2.0-39-powerpc64-smp","version":"3.2.0-39.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-39.62"},{"name":"linux-image-3.2.0-39-virtual","version":"3.2.0-39.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-39.62"},{"name":"linux-image-3.2.0-39-omap","version":"3.2.0-39.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-39.62"},{"name":"linux-image-3.2.0-39-generic","version":"3.2.0-39.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-39.62"},{"name":"linux-image-3.2.0-39-powerpc-smp","version":"3.2.0-39.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-39.62"},{"name":"linux-image-3.2.0-39-highbank","version":"3.2.0-39.62","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.2.0-39.62"}]},"type":"USN","cves_ids":["CVE-2013-0190","CVE-2013-0216","CVE-2013-0217","CVE-2013-0228","CVE-2013-0231","CVE-2013-0268","CVE-2013-0311","CVE-2013-0313","CVE-2013-0349","CVE-2013-1772","CVE-2013-1774"]},{"id":"USN-1781-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-26T14:49:05.982172","description":"\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nA flaw was discovered in the Extended Verification Module (EVM) of the\nLinux kernel. An unprivileged local user code exploit this flaw to cause a\ndenial of service (system crash). (CVE-2013-0313)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA buffer overflow was discovered in the Linux kernel's /dev/kmesg device. A\nlocal user could exploit this flaw to cause a denial of service (system\ncrash). (CVE-2013-1772)\n\nA flaw was discovered in the Edgeort USB serial converter driver when the\ndevice is disconnected while it is in use. A local user could exploit this\nflaw to cause a denial of service (system crash). (CVE-2013-1774)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-ti-omap4","version":"3.2.0-1427.36","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.2.0-1427-omap4","version":"3.2.0-1427.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1427.36"}]},"type":"USN","cves_ids":["CVE-2013-0228","CVE-2013-0268","CVE-2013-0311","CVE-2013-0313","CVE-2013-0349","CVE-2013-1772","CVE-2013-1774"]},{"id":"USN-1769-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-18T22:01:42.131754","description":"Andrew Cooper of Citrix reported a Xen stack corruption in the Linux\nkernel. An unprivileged user in a 32bit PVOPS guest can cause the guest\nkernel to crash, or operate erroneously. (CVE-2013-0190)\n\nA failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nA flaw was discovered in the Linux kernel Xen PCI backend driver. If a PCI\ndevice is assigned to the guest OS, the guest OS could exploit this flaw to\ncause a denial of service on the host. (CVE-2013-0231)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nTommi Rantala discovered a flaw in the a flaw the Linux kernels handling of\ndatagrams packets when the MSG_PEEK flag is specified. An unprivileged\nlocal user could exploit this flaw to cause a denial of service (system\nhang). (CVE-2013-0290)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nA flaw was discovered in the Extended Verification Module (EVM) of the\nLinux kernel. An unprivileged local user code exploit this flaw to cause a\ndenial of service (system crash). (CVE-2013-0313)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux","version":"3.5.0-26.42","description":"Linux kernel","is_source":true},{"name":"linux-image-3.5.0-26-generic","version":"3.5.0-26.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-26.42"},{"name":"linux-image-3.5.0-26-powerpc-smp","version":"3.5.0-26.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-26.42"},{"name":"linux-image-3.5.0-26-highbank","version":"3.5.0-26.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-26.42"},{"name":"linux-image-3.5.0-26-powerpc64-smp","version":"3.5.0-26.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-26.42"},{"name":"linux-image-3.5.0-26-omap","version":"3.5.0-26.42","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.5.0-26.42"}]},"type":"USN","cves_ids":["CVE-2013-0190","CVE-2013-0216","CVE-2013-0217","CVE-2013-0231","CVE-2013-0268","CVE-2013-0290","CVE-2013-0311","CVE-2013-0313","CVE-2013-0349"]},{"id":"USN-1774-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-21T13:13:44.873284","description":"\nAndrew Cooper of Citrix reported a Xen stack corruption in the Linux\nkernel. An unprivileged user in a 32bit PVOPS guest can cause the guest\nkernel to crash, or operate erroneously. (CVE-2013-0190)\n\nA failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nA flaw was discovered in the Linux kernel Xen PCI backend driver. If a PCI\ndevice is assigned to the guest OS, the guest OS could exploit this flaw to\ncause a denial of service on the host. (CVE-2013-0231)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nTommi Rantala discovered a flaw in the a flaw the Linux kernels handling of\ndatagrams packets when the MSG_PEEK flag is specified. An unprivileged\nlocal user could exploit this flaw to cause a denial of service (system\nhang). (CVE-2013-0290)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nA flaw was discovered in the Extended Verification Module (EVM) of the\nLinux kernel. An unprivileged local user code exploit this flaw to cause a\ndenial of service (system crash). (CVE-2013-0313)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n","is_hidden":false,"release_packages":{"quantal":[{"name":"linux-ti-omap4","version":"3.5.0-221.31","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.5.0-221-omap4","version":"3.5.0-221.31","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-221.31"}]},"type":"USN","cves_ids":["CVE-2013-0190","CVE-2013-0216","CVE-2013-0217","CVE-2013-0231","CVE-2013-0268","CVE-2013-0290","CVE-2013-0311","CVE-2013-0313","CVE-2013-0349"]},{"id":"USN-1756-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-06T10:14:04.085387","description":"A failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-32.50","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-32-powerpc64-smp","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-omap","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-generic","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-server","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-powerpc-smp","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-virtual","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-powerpc","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"},{"name":"linux-image-3.0.0-32-generic-pae","version":"3.0.0-32.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-32.50"}]},"type":"USN","cves_ids":["CVE-2013-0216","CVE-2013-0217","CVE-2013-0228","CVE-2013-0268","CVE-2013-0311","CVE-2013-0349","CVE-2013-1773"]},{"id":"USN-1768-1","title":"Linux kernel (Quantal HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-18T21:52:31.826865","description":"Andrew Cooper of Citrix reported a Xen stack corruption in the Linux\nkernel. An unprivileged user in a 32bit PVOPS guest can cause the guest\nkernel to crash, or operate erroneously. (CVE-2013-0190)\n\nA failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nA flaw was discovered in the Linux kernel Xen PCI backend driver. If a PCI\ndevice is assigned to the guest OS, the guest OS could exploit this flaw to\ncause a denial of service on the host. (CVE-2013-0231)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nTommi Rantala discovered a flaw in the a flaw the Linux kernels handling of\ndatagrams packets when the MSG_PEEK flag is specified. An unprivileged\nlocal user could exploit this flaw to cause a denial of service (system\nhang). (CVE-2013-0290)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nA flaw was discovered in the Extended Verification Module (EVM) of the\nLinux kernel. An unprivileged local user code exploit this flaw to cause a\ndenial of service (system crash). (CVE-2013-0313)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-quantal","version":"3.5.0-26.42~precise1","description":"Linux hardware enablement kernel from Quantal","is_source":true},{"name":"linux-image-3.5.0-26-generic","version":"3.5.0-26.42~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-26.42~precise1"}]},"type":"USN","cves_ids":["CVE-2013-0190","CVE-2013-0216","CVE-2013-0217","CVE-2013-0231","CVE-2013-0268","CVE-2013-0290","CVE-2013-0311","CVE-2013-0313","CVE-2013-0349"]},{"id":"USN-1760-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-12T21:03:09.477555","description":"A failure to validate input was discovered in the Linux kernel's Xen\nnetback (network backend) driver. A user in a guest OS may exploit this\nflaw to cause a denial of service to the guest OS and other guest domains.\n(CVE-2013-0216)\n\nA memory leak was discovered in the Linux kernel's Xen netback (network\nbackend) driver. A user in a guest OS could trigger this flaw to cause a\ndenial of service on the system. (CVE-2013-0217)\n\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-32.50~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-32-generic","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"},{"name":"linux-image-3.0.0-32-server","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"},{"name":"linux-image-3.0.0-32-generic-pae","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"},{"name":"linux-image-3.0.0-32-virtual","version":"3.0.0-32.50~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-32.50~lucid1"}]},"type":"USN","cves_ids":["CVE-2013-0216","CVE-2013-0217","CVE-2013-0228","CVE-2013-0268","CVE-2013-0311","CVE-2013-0349","CVE-2013-1773"]},{"id":"USN-1805-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-04-19T07:32:02.091506","description":"Mathias Krause discovered an information leak in the Linux kernel's\ngetsockname implementation for Logical Link Layer (llc) sockets. A local\nuser could exploit this flaw to examine some of the kernel's stack memory.\n(CVE-2012-6542)\n\nMathias Krause discovered information leaks in the Linux kernel's Bluetooth\nLogical Link Control and Adaptation Protocol (L2CAP) implementation. A\nlocal user could exploit these flaws to examine some of the kernel's stack\nmemory. (CVE-2012-6544)\n\nMathias Krause discovered information leaks in the Linux kernel's Bluetooth\nRFCOMM protocol implementation. A local user could exploit these flaws to\nexamine parts of kernel memory. (CVE-2012-6545)\n\nMathias Krause discovered information leaks in the Linux kernel's\nAsynchronous Transfer Mode (ATM) networking stack. A local user could\nexploit these flaws to examine some parts of kernel memory. (CVE-2012-6546)\n\nMathias Krause discovered an information leak in the Linux kernel's UDF\nfile system implementation. A local user could exploit this flaw to examine\nsome of the kernel's heap memory. (CVE-2012-6548)\n\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered in the Edgeort USB serial converter driver when the\ndevice is disconnected while it is in use. A local user could exploit this\nflaw to cause a denial of service (system crash). (CVE-2013-1774)\n\nAndrew Honig discovered a flaw in guest OS time updates in the Linux\nkernel's KVM (Kernel-based Virtual Machine). A privileged guest user could\nexploit this flaw to cause a denial of service (crash host system) or\npotential escalate privilege to the host kernel level. (CVE-2013-1796)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-46.108","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-46-sparc64","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-generic","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-virtual","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-powerpc","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-generic-pae","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-powerpc64-smp","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-preempt","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-server","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-lpia","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-ia64","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-versatile","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-powerpc-smp","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-386","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"},{"name":"linux-image-2.6.32-46-sparc64-smp","version":"2.6.32-46.108","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-46.108"}]},"type":"USN","cves_ids":["CVE-2012-6542","CVE-2012-6544","CVE-2012-6545","CVE-2012-6546","CVE-2012-6548","CVE-2013-0228","CVE-2013-0349","CVE-2013-1774","CVE-2013-1796"]},{"id":"USN-1808-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-04-25T07:52:31.674830","description":"Mathias Krause discovered an information leak in the Linux kernel's\ngetsockname implementation for Logical Link Layer (llc) sockets. A local\nuser could exploit this flaw to examine some of the kernel's stack memory.\n(CVE-2012-6542)\n\nMathias Krause discovered information leaks in the Linux kernel's Bluetooth\nLogical Link Control and Adaptation Protocol (L2CAP) implementation. A\nlocal user could exploit these flaws to examine some of the kernel's stack\nmemory. (CVE-2012-6544)\n\nMathias Krause discovered information leaks in the Linux kernel's Bluetooth\nRFCOMM protocol implementation. A local user could exploit these flaws to\nexamine parts of kernel memory. (CVE-2012-6545)\n\nMathias Krause discovered information leaks in the Linux kernel's\nAsynchronous Transfer Mode (ATM) networking stack. A local user could\nexploit these flaws to examine some parts of kernel memory. (CVE-2012-6546)\n\nMathias Krause discovered an information leak in the Linux kernel's UDF\nfile system implementation. A local user could exploit this flaw to examine\nsome of the kernel's heap memory. (CVE-2012-6548)\n\nAndrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered in the Edgeort USB serial converter driver when the\ndevice is disconnected while it is in use. A local user could exploit this\nflaw to cause a denial of service (system crash). (CVE-2013-1774)\n\nAndrew Honig discovered a flaw in guest OS time updates in the Linux\nkernel's KVM (Kernel-based Virtual Machine). A privileged guest user could\nexploit this flaw to cause a denial of service (crash host system) or\npotential escalate privilege to the host kernel level. (CVE-2013-1796)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-351.64","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-351-ec2","version":"2.6.32-351.64","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-351.64"}]},"type":"USN","cves_ids":["CVE-2012-6542","CVE-2012-6544","CVE-2012-6545","CVE-2012-6546","CVE-2012-6548","CVE-2013-0228","CVE-2013-0349","CVE-2013-1774","CVE-2013-1796"]},{"id":"USN-1778-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2013-03-22T23:36:07.501620","description":"Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's\nXen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged\nguest OS user could exploit this flaw to cause a denial of service (crash\nthe system) or gain guest OS privilege. (CVE-2013-0228)\n\nA flaw was reported in the permission checks done by the Linux kernel for\n/dev/cpu/*/msr. A local root user with all capabilities dropped could\nexploit this flaw to execute code with full root capabilities.\n(CVE-2013-0268)\n\nA flaw was discovered in the Linux kernel's vhost driver used to accelerate\nguest networking in KVM based virtual machines. A privileged guest user\ncould exploit this flaw to crash the host system. (CVE-2013-0311)\n\nAn information leak was discovered in the Linux kernel's Bluetooth stack\nwhen HIDP (Human Interface Device Protocol) support is enabled. A local\nunprivileged user could exploit this flaw to cause an information leak from\nthe kernel. (CVE-2013-0349)\n\nA flaw was discovered on the Linux kernel's VFAT filesystem driver when a\ndisk is mounted with the utf8 option (this is the default on Ubuntu). On a\nsystem where disks/images can be auto-mounted or a FAT filesystem is\nmounted an unprivileged user can exploit the flaw to gain root privileges.\n(CVE-2013-1773)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux-ti-omap4","version":"3.0.0-1222.36","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.0.0-1222-omap4","version":"3.0.0-1222.36","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.0.0-1222.36"}]},"type":"USN","cves_ids":["CVE-2013-0228","CVE-2013-0268","CVE-2013-0311","CVE-2013-0349","CVE-2013-1773"]}]},{"id":"CVE-2013-0339","published":"2013-02-26T00:00:00","updated_at":"2025-08-04T19:24:18.029658+00:00","description":"\nlibxml2 through 2.9.1 does not properly handle external entities expansion\nunless an application developer uses the xmlSAX2ResolveEntity or\nxmlSetExternalEntityLoader function, which allows remote attackers to cause\na denial of service (resource consumption), send HTTP requests to intranet\nservers, or read arbitrary files via a crafted XML document, aka an XML\nExternal Entity (XXE) issue. NOTE: it could be argued that because libxml2\nalready provides the ability to disable external entity expansion, the\nresponsibility for resolving this issue lies with application developers;\naccording to this argument, this entry should be REJECTed and each affected\napplication would need its own CVE.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1904-1","https://www.cve.org/CVERecord?id=CVE-2013-0339"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702260","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0339","https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/1194410"],"patches":{"libxml2":["upstream: https://git.gnome.org/browse/libxml2/commit/?id=4629ee02ac649c27f9c0cf98ba017c6b5526070f"]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"lucid","status":"released","description":"2.7.6.dfsg-1ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.8.dfsg-5.1ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.8.0+dfsg1-5ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"2.9.0+dfsg1-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1904-1"],"notices":[{"id":"USN-1904-1","title":"libxml2 vulnerabilities","summary":"Several security issues were fixed in libxml2.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2013-07-15T13:06:18.084829","description":"It was discovered that libxml2 would load XML external entities by default.\nIf a user or automated system were tricked into opening a specially crafted\ndocument, an attacker could possibly obtain access to arbitrary files or\ncause resource consumption. This issue only affected Ubuntu 10.04 LTS,\nUbuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-0339)\n\nIt was discovered that libxml2 incorrectly handled documents that end\nabruptly. If a user or automated system were tricked into opening a\nspecially crafted document, an attacker could possibly cause libxml2 to\ncrash, resulting in a denial of service. (CVE-2013-2877)\n","is_hidden":false,"release_packages":{"precise":[{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.5","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.5"}],"lucid":[{"name":"libxml2","version":"2.7.6.dfsg-1ubuntu1.9","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.6.dfsg-1ubuntu1.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.6.dfsg-1ubuntu1.9"}],"quantal":[{"name":"libxml2","version":"2.8.0+dfsg1-5ubuntu2.3","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.8.0+dfsg1-5ubuntu2.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.8.0+dfsg1-5ubuntu2.3"}],"raring":[{"name":"libxml2","version":"2.9.0+dfsg1-4ubuntu4.2","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.9.0+dfsg1-4ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.9.0+dfsg1-4ubuntu4.2"}]},"type":"USN","cves_ids":["CVE-2013-0339","CVE-2013-2877"]}]},{"id":"CVE-2013-0338","published":"2013-02-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nlibxml2 2.9.0 and earlier allows context-dependent attackers to cause a\ndenial of service (CPU and memory consumption) via an XML file containing\nan entity declaration with long replacement text and many references to\nthis entity, aka \"internal entity expansion\" with linear complexity.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"PoC in oss-sec"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/02/22/3","https://rhn.redhat.com/errata/RHSA-2013-0581.html","https://ubuntu.com/security/notices/USN-1782-1","https://www.cve.org/CVERecord?id=CVE-2013-0338"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702260","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0338"],"patches":{"libxml2":["upstream: http://git.gnome.org/browse/libxml2/commit/?id=23f05e0c33987d6605387b300c4be5da2120a7ab","vendor: http://www.debian.org/security/2013/dsa-2652"]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"hardy","status":"released","description":"2.6.31.dfsg-2ubuntu1.12","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.7.6.dfsg-1ubuntu1.8","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.7.8.dfsg-4ubuntu0.6","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.7.8.dfsg-5.1ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.8.0+dfsg1-5ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.8.0+dfsg1-7+nmu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1782-1"],"notices":[{"id":"USN-1782-1","title":"libxml2 vulnerability","summary":"libxml2 could be made to hang if it received specially crafted input.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2013-03-28T14:00:16.621627","description":"It was discovered that libxml2 incorrectly handled XML entity expansion.\nAn attacker could use this flaw to cause libxml2 to consume large amounts\nof resources, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"precise":[{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.4","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-5.1ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-5.1ubuntu4.4"}],"hardy":[{"name":"libxml2","version":"2.6.31.dfsg-2ubuntu1.12","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.6.31.dfsg-2ubuntu1.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.6.31.dfsg-2ubuntu1.12"}],"lucid":[{"name":"libxml2","version":"2.7.6.dfsg-1ubuntu1.8","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.6.dfsg-1ubuntu1.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.6.dfsg-1ubuntu1.8"}],"quantal":[{"name":"libxml2","version":"2.8.0+dfsg1-5ubuntu2.2","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.8.0+dfsg1-5ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.8.0+dfsg1-5ubuntu2.2"}],"oneiric":[{"name":"libxml2","version":"2.7.8.dfsg-4ubuntu0.6","description":"GNOME XML library","is_source":true},{"name":"libxml2","version":"2.7.8.dfsg-4ubuntu0.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/libxml2","version_link":"https://launchpad.net/ubuntu/+source/libxml2/2.7.8.dfsg-4ubuntu0.6"}]},"type":"USN","cves_ids":["CVE-2013-0338"]}]},{"id":"CVE-2013-0335","published":"2013-02-26T00:00:00","updated_at":"2026-08-07T17:49:18.069941+00:00","description":"\nOpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1)\nallows remote authenticated users to gain access to a VM in opportunistic\ncircumstances by using the VNC token for a deleted VM that was bound to the\nsame VNC port.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"on 11.10, VNC consoles are only available via the web interface,\nbut the web interface (horizon) is not functional since it depends on\nkeystone and the keystone in 11.10 is a pre-release version and unusable with\nother components like horizon and nova."}],"codename":null,"priority":"low","cvss3":7.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1771-1","https://www.cve.org/CVERecord?id=CVE-2013-0335"],"bugs":["https://launchpad.net/bugs/1125378"],"patches":{"nova":["upstream: https://review.openstack.org/#/c/22086/","upstream: https://review.openstack.org/#/c/22758","upstream: https://review.openstack.org/#/c/22872/","upstream: https://review.openstack.org/#/c/23036/"]},"tags":{},"packages":[{"name":"nova","source":"https://ubuntu.com/security/cve?package=nova","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nova","debian":"https://tracker.debian.org/pkg/nova","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2012.2.1+stable-20121212-a99a802e-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2013.1.g3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1771-1"],"notices":[{"id":"USN-1771-1","title":"OpenStack Nova vulnerabilities","summary":"Two security issues were fixed in Nova.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-03-20T19:21:57.720334","description":"Loganathan Parthipan discovered that Nova did not properly validate VNC\ntokens after an instance was deleted. An authenticated attacker could\nexploit this to access other virtual machines under certain circumstances.\nThis issue did not affect Ubuntu 11.10. (CVE-2013-0335)\n\nVish Ishaya discovered that Nova did not always enforce quotas on fixed\nIPs. An authenticated attacker could exploit this to cause a denial of\nservice via resource consumption. Nova will now enforce a quota limit of\n10 fixed IPs per instance, which is configurable via 'quota_fixed_ips'\nin /etc/nova/nova.conf. (CVE-2013-1838)\n","is_hidden":false,"release_packages":{"precise":[{"name":"nova","version":"2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.4","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"python-nova","version":"2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.4"}],"quantal":[{"name":"nova","version":"2012.2.1+stable-20121212-a99a802e-0ubuntu1.4","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"python-nova","version":"2012.2.1+stable-20121212-a99a802e-0ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/2012.2.1+stable-20121212-a99a802e-0ubuntu1.4"}],"oneiric":[{"name":"nova","version":"2011.3-0ubuntu6.13","description":"OpenStack Compute cloud infrastructure","is_source":true},{"name":"python-nova","version":"2011.3-0ubuntu6.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nova","version_link":"https://launchpad.net/ubuntu/+source/nova/2011.3-0ubuntu6.13"}]},"type":"USN","cves_ids":["CVE-2013-0335","CVE-2013-1838"]}]},{"id":"CVE-2012-4558","published":"2013-02-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in the balancer_handler\nfunction in the manager interface in mod_proxy_balancer.c in the\nmod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev\nand 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web\nscript or HTML via a crafted string.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same commit as CVE-2012-3499"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_balancer.c?r1=1404653&r2=1413732&diff_format=h","http://httpd.apache.org/security/vulnerabilities_22.html","https://ubuntu.com/security/notices/USN-1765-1","https://www.cve.org/CVERecord?id=CVE-2012-4558"],"bugs":[""],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1447390","vendor: http://www.debian.org/security/2013/dsa-2637"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"hardy","status":"released","description":"2.2.8-1ubuntu0.25","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.2.14-5ubuntu8.11","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.2.20-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.2.22-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.2.22-6ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.22-13","component":null,"pocket":"security"}]}],"notices_ids":["USN-1765-1"],"notices":[{"id":"USN-1765-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in the Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-03-18T13:09:18.619857","description":"Niels Heinen discovered that multiple modules incorrectly sanitized certain\nstrings, which could result in browsers becoming vulnerable to cross-site\nscripting attacks when processing the output. With cross-site scripting\nvulnerabilities, if a user were tricked into viewing server output during a\ncrafted server request, a remote attacker could exploit this to modify the\ncontents, or steal confidential data (such as passwords), within the same\ndomain. (CVE-2012-3499, CVE-2012-4558)\n\nIt was discovered that the mod_proxy_ajp module incorrectly handled error\nstates. A remote attacker could use this issue to cause the server to stop\nresponding, resulting in a denial of service. This issue only applied to\nUbuntu 8.04 LTS, Ubuntu 10.04 LTS and Ubuntu 11.10. (CVE-2012-4557)\n\nIt was discovered that the apache2ctl script shipped in Ubuntu packages\nincorrectly created the lock directory. A local attacker could possibly use\nthis issue to gain privileges. The symlink protections in Ubuntu 11.10 and\nlater should reduce this vulnerability to a denial of service.\n(CVE-2013-1048)\n","is_hidden":false,"release_packages":{"precise":[{"name":"apache2","version":"2.2.22-1ubuntu1.3","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.22-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.3"}],"hardy":[{"name":"apache2","version":"2.2.8-1ubuntu0.25","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.8-1ubuntu0.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.25"}],"lucid":[{"name":"apache2","version":"2.2.14-5ubuntu8.11","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.14-5ubuntu8.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.14-5ubuntu8.11"}],"quantal":[{"name":"apache2","version":"2.2.22-6ubuntu2.2","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.22-6ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.22-6ubuntu2.2"}],"oneiric":[{"name":"apache2","version":"2.2.20-1ubuntu1.4","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.20-1ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.20-1ubuntu1.4"}]},"type":"USN","cves_ids":["CVE-2012-3499","CVE-2012-4557","CVE-2012-4558","CVE-2013-1048"]}]},{"id":"CVE-2012-3499","published":"2013-02-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP\nServer 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote\nattackers to inject arbitrary web script or HTML via vectors involving\nhostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4)\nmod_proxy_ftp, and (5) mod_status modules.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://httpd.apache.org/security/vulnerabilities_22.html","https://ubuntu.com/security/notices/USN-1765-1","https://www.cve.org/CVERecord?id=CVE-2012-3499"],"bugs":[""],"patches":{"apache2":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1447390","vendor: http://www.debian.org/security/2013/dsa-2637"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"hardy","status":"released","description":"2.2.8-1ubuntu0.25","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.2.14-5ubuntu8.11","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.2.20-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2.2.22-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2.2.22-6ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.22-13","component":null,"pocket":"security"}]}],"notices_ids":["USN-1765-1"],"notices":[{"id":"USN-1765-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in the Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-03-18T13:09:18.619857","description":"Niels Heinen discovered that multiple modules incorrectly sanitized certain\nstrings, which could result in browsers becoming vulnerable to cross-site\nscripting attacks when processing the output. With cross-site scripting\nvulnerabilities, if a user were tricked into viewing server output during a\ncrafted server request, a remote attacker could exploit this to modify the\ncontents, or steal confidential data (such as passwords), within the same\ndomain. (CVE-2012-3499, CVE-2012-4558)\n\nIt was discovered that the mod_proxy_ajp module incorrectly handled error\nstates. A remote attacker could use this issue to cause the server to stop\nresponding, resulting in a denial of service. This issue only applied to\nUbuntu 8.04 LTS, Ubuntu 10.04 LTS and Ubuntu 11.10. (CVE-2012-4557)\n\nIt was discovered that the apache2ctl script shipped in Ubuntu packages\nincorrectly created the lock directory. A local attacker could possibly use\nthis issue to gain privileges. The symlink protections in Ubuntu 11.10 and\nlater should reduce this vulnerability to a denial of service.\n(CVE-2013-1048)\n","is_hidden":false,"release_packages":{"precise":[{"name":"apache2","version":"2.2.22-1ubuntu1.3","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.22-1ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.3"}],"hardy":[{"name":"apache2","version":"2.2.8-1ubuntu0.25","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.8-1ubuntu0.25","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.8-1ubuntu0.25"}],"lucid":[{"name":"apache2","version":"2.2.14-5ubuntu8.11","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.14-5ubuntu8.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.14-5ubuntu8.11"}],"quantal":[{"name":"apache2","version":"2.2.22-6ubuntu2.2","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.22-6ubuntu2.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.22-6ubuntu2.2"}],"oneiric":[{"name":"apache2","version":"2.2.20-1ubuntu1.4","description":"Apache HTTP server","is_source":true},{"name":"apache2.2-common","version":"2.2.20-1ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.2.20-1ubuntu1.4"}]},"type":"USN","cves_ids":["CVE-2012-3499","CVE-2012-4557","CVE-2012-4558","CVE-2013-1048"]}]},{"id":"CVE-2013-0158","published":"2013-02-24T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Jenkins before 1.498, Jenkins LTS before\n1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before\n1.466.12.1, when a slave is attached and anonymous read access is enabled,\nallows remote attackers to obtain the master cryptographic key via unknown\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-01-04","https://www.cve.org/CVERecord?id=CVE-2013-0158"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697617"],"patches":{"jenkins":[]},"tags":{},"packages":[{"name":"jenkins","source":"https://ubuntu.com/security/cve?package=jenkins","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jenkins","debian":"https://tracker.debian.org/pkg/jenkins","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6074","published":"2013-02-24T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins\nLTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13,\n1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote\nauthenticated users with write access to inject arbitrary web script or\nHTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2012-11-20","http://www.openwall.com/lists/oss-security/2012/12/28/1","https://www.cve.org/CVERecord?id=CVE-2012-6074"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696816"],"patches":{"jenkins":[]},"tags":{},"packages":[{"name":"jenkins","source":"https://ubuntu.com/security/cve?package=jenkins","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jenkins","debian":"https://tracker.debian.org/pkg/jenkins","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.480.1, 1.491","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6073","published":"2013-02-24T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpen redirect vulnerability in Jenkins before 1.491, Jenkins LTS before\n1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before\n1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to\nredirect users to arbitrary web sites and conduct phishing attacks via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2012-11-20","http://www.openwall.com/lists/oss-security/2012/12/28/1","https://www.cve.org/CVERecord?id=CVE-2012-6073"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696816"],"patches":{"jenkins":[]},"tags":{},"packages":[{"name":"jenkins","source":"https://ubuntu.com/security/cve?package=jenkins","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jenkins","debian":"https://tracker.debian.org/pkg/jenkins","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.480.1, 1.491","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6072","published":"2013-02-24T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before\n1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before\n1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to inject\narbitrary HTTP headers and conduct HTTP response splitting attacks via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2012-11-20","http://www.openwall.com/lists/oss-security/2012/12/28/1","https://www.cve.org/CVERecord?id=CVE-2012-6072"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696816","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696974"],"patches":{"jenkins":[],"jenkins-winstone":["upstream: https://github.com/jenkinsci/winstone/commit/62e890b9589a844553d837d91b5f68eb3dba334e"]},"tags":{},"packages":[{"name":"jenkins","source":"https://ubuntu.com/security/cve?package=jenkins","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jenkins","debian":"https://tracker.debian.org/pkg/jenkins","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.480.1, 1.491","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"jenkins-winstone","source":"https://ubuntu.com/security/cve?package=jenkins-winstone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jenkins-winstone","debian":"https://tracker.debian.org/pkg/jenkins-winstone","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.10-jenkins-37+dfsg-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [0.8.10-jenkins-47+dfsg-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6121","published":"2013-02-24T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5\nallows remote attackers to inject arbitrary web script or HTML via a (1)\ndata:text or (2) vbscript link.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/02/07","http://trac.roundcube.net/ticket/1488850","http://sourceforge.net/news/?group_id=139281&id=310213","https://www.cve.org/CVERecord?id=CVE-2012-6121"],"bugs":[""],"patches":{"roundcube":["upstream: https://github.com/roundcube/roundcubemail/commit/74cd0a9b62f11bc07c5a1d3ba0098b54883eb0ba"]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"vivid","status":"not-affected","description":"0.9.5-4","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.9.2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"0.9.5-4","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"0.9.5-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.9.5-4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"0.9.5-4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.9.5-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.9.5-4]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-2697","published":"2013-02-24T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in autofs, as used in Red Hat Enterprise Linux\n(RHEL) 5, allows local users to cause a denial of service (autofs crash and\ndelayed mounts) or prevent \"mount expiration\" via unspecified vectors\nrelated to \"using an LDAP-based automount map.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://rhn.redhat.com/errata/RHSA-2013-0132.html","http://thread.gmane.org/gmane.linux.file-systems/55530","https://www.cve.org/CVERecord?id=CVE-2012-2697"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=831772"],"patches":{"autofs":["upstream: https://git.kernel.org/cgit/linux/storage/autofs/autofs.git/commit/?id=03bbfe8416ce1701a8cdcc50503b2ba89e06870d"],"autofs5":["upstream: https://git.kernel.org/cgit/linux/storage/autofs/autofs.git/commit/?id=03bbfe8416ce1701a8cdcc50503b2ba89e06870d"]},"tags":{},"packages":[{"name":"autofs","source":"https://ubuntu.com/security/cve?package=autofs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=autofs","debian":"https://tracker.debian.org/pkg/autofs","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"5.0.7-3ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"autofs5","source":"https://ubuntu.com/security/cve?package=autofs5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=autofs5","debian":"https://tracker.debian.org/pkg/autofs5","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"5.0.6-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0220","published":"2013-02-24T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe (1) sss_autofs_cmd_getautomntent and (2)\nsss_autofs_cmd_getautomntbyname function in\nresponder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function\nin responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD)\nbefore 1.9.4 allow remote attackers to cause a denial of service\n(out-of-bounds read, crash, and restart) via a crafted SSSD packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-0220"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698871","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0220"],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0219","published":"2013-02-24T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSystem Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2)\ncopying, or (3) removing a user home directory tree, allows local users to\ncreate, modify, or delete arbitrary files via a symlink attack on another\nuser's files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-0219"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698871","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-0219"],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"wily","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.9.3-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6128","published":"2013-02-24T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple stack-based buffer overflows in http.c in OpenConnect before 4.08\nallow remote VPN gateways to cause a denial of service (application crash)\nvia a long (1) hostname, (2) path, or (3) cookie list in a response.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/02/12/7","https://www.cve.org/CVERecord?id=CVE-2012-6128"],"bugs":[""],"patches":{"openconnect":["upstream: http://git.infradead.org/users/dwmw2/openconnect.git/commit/26f752c3dbf69227679fc6bebb4ae071aecec491"]},"tags":{"openconnect":["stack-protector"]},"packages":[{"name":"openconnect","source":"https://ubuntu.com/security/cve?package=openconnect","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openconnect","debian":"https://tracker.debian.org/pkg/openconnect","statuses":[{"release_codename":"vivid","status":"not-affected","description":"5.02-1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"5.01-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.99","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.02-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"5.02-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"5.02-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"5.02-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"5.02-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [5.02-1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-0786","published":"2013-02-24T11:48:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x\nbefore 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error\nmessages for invalid product queries depending on whether a product exists,\nwhich allows remote attackers to discover private product names by using\ndebug mode for a query.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.mozilla.org/show_bug.cgi?id=824399","http://www.bugzilla.org/security/3.6.12/","https://www.cve.org/CVERecord?id=CVE-2013-0786"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":67960,"limit":20,"total_results":79316}