{"cves":[{"id":"CVE-2013-0247","published":"2013-02-05T15:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier,\nand Grizzly grizzly-2 and earlier allows remote attackers to cause a denial\nof service (disk consumption) via many invalid token requests that trigger\nexcessive generation of log entries.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Keystone on 11.10 is a pre-release version and unusable with other\ncomponents such as nova and horizon\n2013.1~g2-0ubuntu1 is affected. Server team will provide this as\npart of their regular updates for Ubuntu 13.04 (deferring for now)\nreproducer in the bug"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://lists.openstack.org/pipermail/openstack-announce/2013-February/000074.html","https://ubuntu.com/security/notices/USN-1715-1","https://www.cve.org/CVERecord?id=CVE-2013-0247"],"bugs":["https://bugs.launchpad.net/keystone/+bug/1098307"],"patches":{"keystone":[]},"tags":{},"packages":[{"name":"keystone","source":"https://ubuntu.com/security/cve?package=keystone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=keystone","debian":"https://tracker.debian.org/pkg/keystone","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"2012.1+stable~20120824-a16a0ab9-0ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"2012.2.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1715-1"],"notices":[{"id":"USN-1715-1","title":"OpenStack Keystone vulnerability","summary":"Keystone could be made to fill server disks with error messages.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-02-05T21:54:37.141933","description":"Dan Prince discovered that Keystone did not properly perform input\nvalidation when handling certain error conditions. An unauthenticated user\ncould exploit this to cause a denial of service in Keystone API servers via\ndisk space exhaustion.\n","is_hidden":false,"release_packages":{"precise":[{"name":"keystone","version":"2012.1+stable~20120824-a16a0ab9-0ubuntu2.4","description":"OpenStack identity service","is_source":true},{"name":"python-keystone","version":"2012.1+stable~20120824-a16a0ab9-0ubuntu2.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/keystone","version_link":"https://launchpad.net/ubuntu/+source/keystone/2012.1+stable~20120824-a16a0ab9-0ubuntu2.4"}],"quantal":[{"name":"keystone","version":"2012.2.1-0ubuntu1.1","description":"OpenStack identity service","is_source":true},{"name":"python-keystone","version":"2012.2.1-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/keystone","version_link":"https://launchpad.net/ubuntu/+source/keystone/2012.2.1-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2013-0247"]}]},{"id":"CVE-2013-1799","published":"2013-02-05T00:00:00","updated_at":"2025-08-04T19:24:19.235787+00:00","description":"\nGnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91,\ndoes not properly validate SSL certificates when creating accounts for\nproviders who use the libsoup library, which allows man-in-the-middle\nattackers to obtain sensitive information such as credentials by sniffing\nthe network. NOTE: this issue exists because of an incomplete fix for\nCVE-2013-0240.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"CVE-2013-1799 is a result of an incomplete fix for CVE-2013-0240"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1779-1","https://www.cve.org/CVERecord?id=CVE-2013-1799"],"bugs":[""],"patches":{"gnome-online-accounts":[]},"tags":{},"packages":[{"name":"gnome-online-accounts","source":"https://ubuntu.com/security/cve?package=gnome-online-accounts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnome-online-accounts","debian":"https://tracker.debian.org/pkg/gnome-online-accounts","statuses":[{"release_codename":"quantal","status":"released","description":"3.6.0-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.2.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.4.0-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.2-2,3.6.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1779-1"],"notices":[{"id":"USN-1779-1","title":"GNOME Online Accounts vulnerability","summary":"GNOME Online Accounts could be made to expose sensitive information over\nthe network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-03-25T14:02:25.482003","description":"It was discovered that GNOME Online Accounts did not properly check SSL\ncertificates when configuring online accounts. If a remote attacker were\nable to perform a machine-in-the-middle attack, this flaw could be exploited to\nalter or compromise credentials and confidential information.\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"gnome-online-accounts","version":"3.2.1-0ubuntu1.1","description":"GNOME Online Accounts","is_source":true},{"name":"gnome-online-accounts","version":"3.2.1-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.2.1-0ubuntu1.1"},{"name":"libgoa-1.0-0","version":"3.2.1-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.2.1-0ubuntu1.1"}],"precise":[{"name":"gnome-online-accounts","version":"3.4.0-0ubuntu1.1","description":"GNOME Online Accounts","is_source":true},{"name":"gnome-online-accounts","version":"3.4.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.4.0-0ubuntu1.1"},{"name":"libgoa-1.0-0","version":"3.4.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.4.0-0ubuntu1.1"}],"quantal":[{"name":"gnome-online-accounts","version":"3.6.0-0ubuntu1.1","description":"GNOME Online Accounts","is_source":true},{"name":"gnome-online-accounts","version":"3.6.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.6.0-0ubuntu1.1"},{"name":"libgoa-1.0-0","version":"3.6.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.6.0-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2013-0240","CVE-2013-1799"]}]},{"id":"CVE-2013-0252","published":"2013-02-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nboost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48\nthrough 1.52 does not properly detect certain invalid UTF-8 sequences,\nwhich might allow remote attackers to bypass input validation protection\nmechanisms via crafted trailing bytes.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu 10.04 LTS and 11.10 not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.boost.org/users/news/boost_locale_security_notice.html","https://ubuntu.com/security/notices/USN-1727-1","https://www.cve.org/CVERecord?id=CVE-2013-0252"],"bugs":["https://svn.boost.org/trac/boost/ticket/7743","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699649 (1.49)","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699650 (1.50)"],"patches":{"boost1.40":[],"boost1.42":[],"boost1.48":["upstream: cppcms.com/files/locale/boost_locale_utf.patch"],"boost1.49":["upstream: cppcms.com/files/locale/boost_locale_utf.patch","upstream: https://svn.boost.org/trac/boost/changeset/81590"],"boost1.50":["upstream: cppcms.com/files/locale/boost_locale_utf.patch"]},"tags":{},"packages":[{"name":"boost1.40","source":"https://ubuntu.com/security/cve?package=boost1.40","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boost1.40","debian":"https://tracker.debian.org/pkg/boost1.40","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"boost1.42","source":"https://ubuntu.com/security/cve?package=boost1.42","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boost1.42","debian":"https://tracker.debian.org/pkg/boost1.42","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"boost1.48","source":"https://ubuntu.com/security/cve?package=boost1.48","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boost1.48","debian":"https://tracker.debian.org/pkg/boost1.48","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"boost1.49","source":"https://ubuntu.com/security/cve?package=boost1.49","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boost1.49","debian":"https://tracker.debian.org/pkg/boost1.49","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"1.49.0-3.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"1.49.0-3.2ubuntu1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"1.49.0-3.2ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.49.0-3.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"boost1.50","source":"https://ubuntu.com/security/cve?package=boost1.50","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=boost1.50","debian":"https://tracker.debian.org/pkg/boost1.50","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1727-1"],"notices":[{"id":"USN-1727-1","title":"Boost vulnerability","summary":"Boost incorrectly validated certain UTF-8 sequences.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-02-18T13:42:57.126644","description":"It was discovered that the Boost.Locale library incorrectly validated some\ninvalid UTF-8 sequences. An attacker could possibly use this issue to\nbypass input validation in certain applications.\n","is_hidden":false,"release_packages":{"quantal":[{"name":"boost1.49","version":"1.49.0-3.1ubuntu1.2","description":"C++ representation of time duration, time point, and clocks","is_source":true},{"name":"libboost-locale1.49.0","version":"1.49.0-3.1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/boost1.49","version_link":"https://launchpad.net/ubuntu/+source/boost1.49/1.49.0-3.1ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2013-0252"]}]},{"id":"CVE-2013-0240","published":"2013-02-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before\n3.7.5, does not properly validate SSL certificates when creating accounts\nsuch as Windows Live and Facebook accounts, which allows man-in-the-middle\nattackers to obtain sensitive information such as credentials by sniffing\nthe network.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"3.2 in oneiric and 3.4 in precise only have web backends, so\nthe 3.4 patch will work. In 3.6+, more backends are available\nthat may have invalid certs, but are desirable. The 3.7 patch\nadds a new configuration item, but this changes API."},{"author":"jdstrand","note":"note that CVE-2013-1799 is a result of an incomplete fix for this\nCVE (and pt2 of the patch for 3.6)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1779-1","https://www.cve.org/CVERecord?id=CVE-2013-0240"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699825","https://launchpad.net/bugs/1117411","https://bugzilla.gnome.org/show_bug.cgi?id=693214","https://bugzilla.redhat.com/show_bug.cgi?id=894352"],"patches":{"gnome-online-accounts":["upstream: http://git.gnome.org/browse/gnome-online-accounts/commit/?id=edde7c63326242a60a075341d3fea0be0bc4d80e","upstream: http://git.gnome.org/browse/gnome-online-accounts/commit/?id=d5d229529c498ab8b19c29080dd79930fd353d93","upstream: http://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-4&id=5a3d3862b0765385f38ca1ba2a9e2e74eb0d111d","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=ecad8142e9ac519b9fc74b96dcb5531052bbffe1","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=de6ee1fa825297c6c89cddb767f4da8df6dbfca2","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=232bffd1dae3e708f06d83fd802a2218e43ebc5d","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=229a82872b4c5399c1d3793c46ba5d3e19e1a8ee","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=55f1171b15d5c307894943a6b753dd8e59b1452d","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=03aa82a3777885fe3a06db02621852f1f8c429d8","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=012dbc6d6cac1ad1696dd11b96ee389f0efbb134","upstream: https://git.gnome.org/browse/gnome-online-accounts/commit/?h=gnome-3-6&id=9cf4bc0ced2c53bcdd36922caa65afc8a167bbd8"]},"tags":{},"packages":[{"name":"gnome-online-accounts","source":"https://ubuntu.com/security/cve?package=gnome-online-accounts","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnome-online-accounts","debian":"https://tracker.debian.org/pkg/gnome-online-accounts","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.2.1-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"3.4.0-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"3.6.0-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.2-2,3.6.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1779-1"],"notices":[{"id":"USN-1779-1","title":"GNOME Online Accounts vulnerability","summary":"GNOME Online Accounts could be made to expose sensitive information over\nthe network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2013-03-25T14:02:25.482003","description":"It was discovered that GNOME Online Accounts did not properly check SSL\ncertificates when configuring online accounts. If a remote attacker were\nable to perform a machine-in-the-middle attack, this flaw could be exploited to\nalter or compromise credentials and confidential information.\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"gnome-online-accounts","version":"3.2.1-0ubuntu1.1","description":"GNOME Online Accounts","is_source":true},{"name":"gnome-online-accounts","version":"3.2.1-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.2.1-0ubuntu1.1"},{"name":"libgoa-1.0-0","version":"3.2.1-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.2.1-0ubuntu1.1"}],"precise":[{"name":"gnome-online-accounts","version":"3.4.0-0ubuntu1.1","description":"GNOME Online Accounts","is_source":true},{"name":"gnome-online-accounts","version":"3.4.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.4.0-0ubuntu1.1"},{"name":"libgoa-1.0-0","version":"3.4.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.4.0-0ubuntu1.1"}],"quantal":[{"name":"gnome-online-accounts","version":"3.6.0-0ubuntu1.1","description":"GNOME Online Accounts","is_source":true},{"name":"gnome-online-accounts","version":"3.6.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.6.0-0ubuntu1.1"},{"name":"libgoa-1.0-0","version":"3.6.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts","version_link":"https://launchpad.net/ubuntu/+source/gnome-online-accounts/3.6.0-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2013-0240","CVE-2013-1799"]}]},{"id":"CVE-2013-1590","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the NTLMSSP dissector in Wireshark 1.6.x before 1.6.13\nand 1.8.x before 1.8.5 allows remote attackers to cause a denial of service\n(application crash) via a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-09.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1590"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1589","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDouble free vulnerability in epan/proto.c in the dissection engine in\nWireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote\nattackers to cause a denial of service (application crash) via a malformed\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-08.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1589"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8197"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1588","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in the dissect_pft_fec_detailed function in the\nDCP-ETSI dissector in epan/dissectors/packet-dcp-etsi.c in Wireshark 1.6.x\nbefore 1.6.13 and 1.8.x before 1.8.5 allow remote attackers to cause a\ndenial of service (application crash) via a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-07.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1588"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8213"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1587","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_rohc_ir_packet function in epan/dissectors/packet-rohc.c in the\nROHC dissector in Wireshark 1.8.x before 1.8.5 does not properly handle\nunknown profiles, which allows remote attackers to cause a denial of\nservice (application crash) via a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-06.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1587"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7679"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1586","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe fragment_set_tot_len function in epan/reassemble.c in Wireshark 1.6.x\nbefore 1.6.13 and 1.8.x before 1.8.5 does not properly determine the length\nof a reassembled packet for the DTLS dissector, which allows remote\nattackers to cause a denial of service (application crash) via a malformed\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-05.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1586"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8111"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1585","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nepan/tvbuff.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does\nnot properly validate certain length values for the MS-MMC dissector, which\nallows remote attackers to cause a denial of service (application crash)\nvia a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-04.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1585"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8112"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1584","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_version_5_and_6_primary_header function in\nepan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before\n1.6.13 and 1.8.x before 1.8.5 accesses an inappropriate pointer, which\nallows remote attackers to cause a denial of service (application crash)\nvia a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-03.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1584"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7945"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1583","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_version_4_primary_header function in\nepan/dissectors/packet-dtn.c in the DTN dissector in Wireshark 1.6.x before\n1.6.13 and 1.8.x before 1.8.5 accesses an inappropriate pointer, which\nallows remote attackers to cause a denial of service (application crash)\nvia a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-03.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1583"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7945"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1582","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_clnp function in epan/dissectors/packet-clnp.c in the CLNP\ndissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not\nproperly manage an offset variable, which allows remote attackers to cause\na denial of service (infinite loop or application crash) via a malformed\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-02.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1582"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7871"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1581","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_pft_fec_detailed function in epan/dissectors/packet-dcp-etsi.c\nin the DCP-ETSI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before\n1.8.5 does not properly handle fragment gaps, which allows remote attackers\nto cause a denial of service (loop) via a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.openwall.com/lists/oss-security/2013/01/31/2","http://www.wireshark.org/security/wnpa-sec-2013-01.html","https://www.cve.org/CVERecord?id=CVE-2013-1581"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8222"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1580","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_cmstatus_tlv function in plugins/docsis/packet-cmstatus.c in\nthe DOCSIS CM-STATUS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x\nbefore 1.8.5 uses an incorrect data type for a position variable, which\nallows remote attackers to cause a denial of service (infinite loop) via a\nmalformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-01.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1580"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8199"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1579","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe rtps_util_add_bitmap function in epan/dissectors/packet-rtps.c in the\nRTPS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does\nnot properly implement certain nested loops for processing bitmap data,\nwhich allows remote attackers to cause a denial of service (infinite loop)\nvia a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-01.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1579"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8198"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1578","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_pw_eth_heuristic function in epan/dissectors/packet-pw-eth.c in\nWireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly\nhandle apparent Ethernet address values at the beginning of MPLS data,\nwhich allows remote attackers to cause a denial of service (loop) via a\nmalformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-01.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1578"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8043"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1577","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_sip_p_charging_func_addresses function in\nepan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.6.x before\n1.6.13 and 1.8.x before 1.8.5 does not properly handle offset data\nassociated with a quoted string, which allows remote attackers to cause a\ndenial of service (infinite loop) via a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-01.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1577"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8042"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1576","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_sdp_media_attribute function in epan/dissectors/packet-sdp.c in\nthe SDP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5\ndoes not properly process crypto-suite parameters, which allows remote\nattackers to cause a denial of service (infinite loop) via a malformed\npacket.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-01.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1576"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8041"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-1575","published":"2013-02-03T01:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe dissect_r3_cmd_alarmconfigure function in\nepan/dissectors/packet-assa_r3.c in the R3 dissector in Wireshark 1.6.x\nbefore 1.6.13 and 1.8.x before 1.8.5 does not properly handle a certain\nalarm length, which allows remote attackers to cause a denial of service\n(infinite loop) via a malformed packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/01/30","http://www.wireshark.org/security/wnpa-sec-2013-01.html","http://www.openwall.com/lists/oss-security/2013/01/31/2","https://www.cve.org/CVERecord?id=CVE-2013-1575"],"bugs":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8040"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.10.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13,1.8.5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.12.0+git+4fab41a1-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.12.1+g01b65bf-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":68100,"limit":20,"total_results":79316}