{"cves":[{"id":"CVE-2012-1262","published":"2012-03-03T04:04:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in\nMovable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the\nproduct is incompletely installed, allows remote attackers to inject\narbitrary web script or HTML via the dbuser parameter, a different\nvulnerability than CVE-2012-0318.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.trustwave.com/spiderlabs/advisories/TWSL2012-003.txt","http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html","https://www.cve.org/CVERecord?id=CVE-2012-1262"],"bugs":[""],"patches":{"movabletype-opensource":[]},"tags":{},"packages":[{"name":"movabletype-opensource","source":"https://ubuntu.com/security/cve?package=movabletype-opensource","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=movabletype-opensource","debian":"https://tracker.debian.org/pkg/movabletype-opensource","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.1.4+dfsg-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0320","published":"2012-03-03T04:04:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMovable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allows\nremote attackers to take control of sessions via unspecified vectors\nrelated to the (1) commenting feature and (2) community script.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html","https://www.cve.org/CVERecord?id=CVE-2012-0320"],"bugs":[""],"patches":{"movabletype-opensource":[]},"tags":{},"packages":[{"name":"movabletype-opensource","source":"https://ubuntu.com/security/cve?package=movabletype-opensource","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=movabletype-opensource","debian":"https://tracker.debian.org/pkg/movabletype-opensource","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.1.4+dfsg-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0319","published":"2012-03-03T04:04:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe file-management system in Movable Type before 4.38, 5.0x before 5.07,\nand 5.1x before 5.13 allows remote authenticated users to execute arbitrary\ncommands by leveraging the file-upload feature, related to an \"OS Command\nInjection\" issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html","https://www.cve.org/CVERecord?id=CVE-2012-0319"],"bugs":[""],"patches":{"movabletype-opensource":[]},"tags":{},"packages":[{"name":"movabletype-opensource","source":"https://ubuntu.com/security/cve?package=movabletype-opensource","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=movabletype-opensource","debian":"https://tracker.debian.org/pkg/movabletype-opensource","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.1.4+dfsg-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0318","published":"2012-03-03T04:04:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in Movable Type before\n4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to\ninject arbitrary web script or HTML via vectors involving templates, a\ndifferent issue than CVE-2012-1262.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html","https://www.cve.org/CVERecord?id=CVE-2012-0318"],"bugs":[""],"patches":{"movabletype-opensource":[]},"tags":{},"packages":[{"name":"movabletype-opensource","source":"https://ubuntu.com/security/cve?package=movabletype-opensource","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=movabletype-opensource","debian":"https://tracker.debian.org/pkg/movabletype-opensource","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.1.4+dfsg-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0317","published":"2012-03-03T04:04:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site request forgery (CSRF) vulnerabilities in Movable Type\nbefore 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers\nto hijack the authentication of arbitrary users for requests that modify\ndata via the (1) commenting feature or (2) community script.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.movabletype.org/2012/02/movable_type_513_507_and_438_security_updates.html","https://www.cve.org/CVERecord?id=CVE-2012-0317"],"bugs":[""],"patches":{"movabletype-opensource":[]},"tags":{},"packages":[{"name":"movabletype-opensource","source":"https://ubuntu.com/security/cve?package=movabletype-opensource","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=movabletype-opensource","debian":"https://tracker.debian.org/pkg/movabletype-opensource","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.8","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"5.1.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [5.1.4+dfsg-1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0838","published":"2012-03-02T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nApache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression\nduring the handling of a conversion error, which allows remote attackers to\nmodify run-time data values, and consequently execute arbitrary code, via\ninvalid input to a field.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://jvndb.jvn.jp/jvndb/JVNDB-2012-000012","https://www.cve.org/CVERecord?id=CVE-2012-0838"],"bugs":["https://issues.apache.org/jira/browse/WW-3668"],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.3.1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [code not present]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3443","published":"2012-03-02T00:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in WebKit, as used in Apple Safari before\n5.0.6, allows remote attackers to execute arbitrary code or cause a denial\nof service (heap memory corruption and application crash) via vectors\nrelated to improper list management for Cascading Style Sheets (CSS)\n@font-face rules.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3443"],"bugs":["http://support.apple.com/kb/HT4808"],"patches":{"webkit":[],"webkitgtk":[],"qtwebkit-source":[]},"tags":{},"packages":[{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [no update available]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.4.9-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-1410","published":"2012-02-29T11:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple cross-site scripting (XSS) vulnerabilities in the History Window\nimplementation in Kadu 0.9.0 through 0.11.0 allow remote attackers to\ninject arbitrary web script or HTML via a crafted (1) SMS message, (2)\npresence message, or (3) status description.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2012-1410"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=797777","https://bugzilla.novell.com/show_bug.cgi?id=749036"],"patches":{"kadu":["upstream: https://gitorious.org/kadu/kadu/commit/ebe3674cf0f3aa9b36308c06e19cb293cc790b52","upstream: https://gitorious.org/kadu/kadu/commit/e9506be6d3dcdd408fdf83d8eb82416c9b798c84","upstream: https://gitorious.org/kadu/kadu/commit/94e7479617d78a1649a0763960edade7ad09a0d0","upstream: https://gitorious.org/kadu/kadu/commit/91772e46541e22cbc2c7bf41a1a9798c2a58f6d6"]},"tags":{},"packages":[{"name":"kadu","source":"https://ubuntu.com/security/cve?package=kadu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kadu","debian":"https://tracker.debian.org/pkg/kadu","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.6.5.4.ds1-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"0.11.1-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"0.11.1-2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"0.11.1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"0.11.1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2006-7250","published":"2012-02-29T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and\nearlier allows remote attackers to cause a denial of service (NULL pointer\ndereference and application crash) via a crafted S/MIME message.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"note that 22144 was incorrect and 22243 fixes it and an additional\nissue\nCryptographic Message Syntax was introduced in 0.9.8h"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1424-1","https://www.cve.org/CVERecord?id=CVE-2006-7250"],"bugs":["http://rt.openssl.org/Ticket/Display.html?id=2711&user=guest&pass=guest","https://bugzilla.redhat.com/show_bug.cgi?id=798100","https://bugzilla.novell.com/show_bug.cgi?id=748738"],"patches":{"openssl":["upstream: http://cvs.openssl.org/chngview?cn=22144 and http://cvs.openssl.org/chngview?cn=22243"],"openssl098":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"hardy","status":"not-affected","description":"0.9.8g-4ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.9.8k-7ubuntu8.10","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"0.9.8o-5ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"1.0.0e-2ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.1-1","component":null,"pocket":"security"}]},{"name":"openssl098","source":"https://ubuntu.com/security/cve?package=openssl098","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl098","debian":"https://tracker.debian.org/pkg/openssl098","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"0.9.8o-7ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1424-1"],"notices":[{"id":"USN-1424-1","title":"OpenSSL vulnerabilities","summary":"An application using OpenSSL could be made to crash or run programs if it\nopened a specially crafted file.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-04-19T22:04:27.233639","description":"It was discovered that OpenSSL could be made to dereference a NULL pointer\nwhen processing S/MIME messages. A remote attacker could use this to cause\na denial of service. These issues did not affect Ubuntu 8.04 LTS.\n(CVE-2006-7250, CVE-2012-1165)\n\nTavis Ormandy discovered that OpenSSL did not properly perform bounds\nchecking when processing DER data via BIO or FILE functions. A remote\nattacker could trigger this flaw in services that used SSL to cause a\ndenial of service or possibly execute arbitrary code with application\nprivileges. (CVE-2012-2110)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openssl","version":"0.9.8g-4ubuntu3.17","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl0.9.8","version":"0.9.8g-4ubuntu3.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8g-4ubuntu3.17"}],"lucid":[{"name":"openssl","version":"0.9.8k-7ubuntu8.10","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl0.9.8","version":"0.9.8k-7ubuntu8.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8k-7ubuntu8.10"}],"natty":[{"name":"openssl","version":"0.9.8o-5ubuntu1.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl0.9.8","version":"0.9.8o-5ubuntu1.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/0.9.8o-5ubuntu1.4"}],"oneiric":[{"name":"openssl","version":"1.0.0e-2ubuntu4.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.0e-2ubuntu4.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.0e-2ubuntu4.4"}]},"type":"USN","cves_ids":["CVE-2006-7250","CVE-2012-2110","CVE-2012-1165"]}]},{"id":"CVE-2012-1090","published":"2012-02-28T00:00:00","updated_at":"2026-07-04T07:34:14.454335+00:00","description":"\nThe cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10\nallows local users to cause a denial of service (OOPS) via attempted access\nto a special file, as demonstrated by a FIFO.\n\"The cifs code will attempt to open files on lookup under certain\ncircumstances. What happens though if we find that the file we opened\nwas actually a FIFO or other special file? Currently, the open\nfilehandle just ends up being leaked leading to a dentry refcount\nmismatch and oops on umount.\"","ubuntu_description":"\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service.","notes":[{"author":"apw","note":"currently sitting in the master branch of the tree below, waiting\non merge with linus:\ngit://git.samba.org/sfrench/cifs-2.6\nsee:\ncifs: fix dentry refcount leak when opening a FIFO on lookup\nnow upstream (see below)"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://thread.gmane.org/gmane.linux.kernel.cifs/5526","http://www.openwall.com/lists/oss-security/2012/02/28/3","https://ubuntu.com/security/notices/USN-1405-1","https://ubuntu.com/security/notices/USN-1425-1","https://ubuntu.com/security/notices/USN-1426-1","https://ubuntu.com/security/notices/USN-1431-1","https://ubuntu.com/security/notices/USN-1433-1","https://ubuntu.com/security/notices/USN-1432-1","https://ubuntu.com/security/notices/USN-1440-1","https://ubuntu.com/security/notices/USN-1446-1","https://ubuntu.com/security/notices/USN-1458-1","https://www.cve.org/CVERecord?id=CVE-2012-1090"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=798293","https://launchpad.net/bugs/947997"],"patches":{"linux":["break-fix: 8db14ca12569fe885694bd3d5ff84c2d973d3cb0 5bccda0ebc7c0331b81ac47d39e4b920b198b2cd"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-lts-trusty":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-raspi2":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe-edge":[],"linux-hwe":[],"linux-gke":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-41.88","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-15.59","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-18.31","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-19.30","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.4.0-1.1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.7.0-0.5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.9.0-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.13.0-24.46","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.16.0-23.31","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.19.0-15.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1601.4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1601.4","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-345.47","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.10","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.18","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-3.15","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.3]","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-3.14","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-4.23","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-4.24","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"3.4.0-4.27","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-1.9]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.38-15.59~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.0-18.31~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.5.0-18.29~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.8.0-19.30~precise1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.13.0-24.46~precise1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.16.0-25.33~14.04.2]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [4.2.0-18.22~14.04.1]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-5.28","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-6.37","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"3.4.0-5.34","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-3.21]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"3.4.0-6.25","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"3.4.0-6.29","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"3.4.0-7.32","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.4.0-4.19]","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"4.2.0-1008.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.24","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"3.0.0-1208.19","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1412.15","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1410.13","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.2.0-1410.13","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"3.5.0-223.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3~rc7","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1440-1","USN-1425-1","USN-1433-1","USN-1446-1","USN-1432-1","USN-1431-1","USN-1426-1","USN-1458-1"],"notices":[{"id":"USN-1440-1","title":"Linux kernel (Natty backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-08T07:41:27.732519","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's ext4 file system when mounting a\ncorrupt filesystem. A user-assisted remote attacker could exploit this flaw\nto cause a denial of service. (CVE-2012-2100)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-natty","version":"2.6.38-15.59~lucid1","description":"Linux kernel backport from Natty","is_source":true},{"name":"linux-image-2.6.38-15-generic","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"},{"name":"linux-image-2.6.38-15-virtual","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"},{"name":"linux-image-2.6.38-15-generic-pae","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"},{"name":"linux-image-2.6.38-15-server","version":"2.6.38-15.59~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-15.59~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4086","CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-1146","CVE-2012-2100","CVE-2012-4398"]},{"id":"USN-1425-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-04-24T10:21:17.098314","description":"\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-41.88","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-41-server","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-preempt","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-ia64","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-generic-pae","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-386","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-generic","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-powerpc","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-sparc64","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-sparc64-smp","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-powerpc-smp","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-virtual","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-powerpc64-smp","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-versatile","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"},{"name":"linux-image-2.6.32-41-lpia","version":"2.6.32-41.88","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-41.88"}]},"type":"USN","cves_ids":["CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-4398"]},{"id":"USN-1433-1","title":"Linux kernel (Oneiric backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-01T05:24:25.806687","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's handling of paged memory. A local\nunprivileged user, or a privileged user within a KVM guest, could exploit\nthis flaw to crash the system. (CVE-2012-1179)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-oneiric","version":"3.0.0-19.33~lucid1","description":"Linux kernel backport from Oneiric","is_source":true},{"name":"linux-image-3.0.0-19-generic-pae","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"},{"name":"linux-image-3.0.0-19-server","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"},{"name":"linux-image-3.0.0-19-generic","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"},{"name":"linux-image-3.0.0-19-virtual","version":"3.0.0-19.33~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-oneiric/3.0.0-19.33~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-4086","CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-1146","CVE-2012-1179","CVE-2012-4398"]},{"id":"USN-1446-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-18T01:27:31.745972","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's handling of paged memory. A local\nunprivileged user, or a privileged user within a KVM guest, could exploit\nthis flaw to crash the system. (CVE-2012-1179)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux-ti-omap4","version":"3.0.0-1209.21","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-3.0.0-1209-omap4","version":"3.0.0-1209.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.0.0-1209.21"}]},"type":"USN","cves_ids":["CVE-2011-4086","CVE-2012-1090","CVE-2012-1097","CVE-2012-1146","CVE-2012-1179","CVE-2012-4398"]},{"id":"USN-1432-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-08T05:59:08.139927","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nA flaw was found in the Linux kernel's ext4 file system when mounting a\ncorrupt filesystem. A user-assisted remote attacker could exploit this flaw\nto cause a denial of service. (CVE-2012-2100)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-15.59","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-15-powerpc","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-omap","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-generic-pae","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-server","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-powerpc64-smp","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-virtual","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-versatile","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-generic","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"},{"name":"linux-image-2.6.38-15-powerpc-smp","version":"2.6.38-15.59","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-15.59"}]},"type":"USN","cves_ids":["CVE-2011-4086","CVE-2012-1090","CVE-2012-2100","CVE-2012-4398"]},{"id":"USN-1431-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-05-01T03:41:26.564188","description":"\nA flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's handling of paged memory. A local\nunprivileged user, or a privileged user within a KVM guest, could exploit\nthis flaw to crash the system. (CVE-2012-1179)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"linux","version":"3.0.0-19.33","description":"Linux kernel","is_source":true},{"name":"linux-image-3.0.0-19-generic-pae","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-powerpc","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-server","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-omap","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-generic","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-powerpc-smp","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-powerpc64-smp","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"},{"name":"linux-image-3.0.0-19-virtual","version":"3.0.0-19.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.0.0-19.33"}]},"type":"USN","cves_ids":["CVE-2012-4398","CVE-2012-1090","CVE-2012-1179","CVE-2011-4086","CVE-2011-4347","CVE-2012-0045","CVE-2012-1097","CVE-2012-1146"]},{"id":"USN-1426-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-04-24T10:29:11.445329","description":"\nSasha Levin discovered a flaw in the permission checking for device\nassignments requested via the kvm ioctl in the Linux kernel. A local user\ncould use this flaw to crash the system causing a denial of service.\n(CVE-2011-4347)\n\nStephan Bärwolf discovered a flaw in the KVM (kernel-based virtual\nmachine) subsystem of the Linux kernel. A local unprivileged user can crash\nuse this flaw to crash VMs causing a deny of service. (CVE-2012-0045)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nTetsuo Handa reported a flaw in the OOM (out of memory) killer of the Linux\nkernel. A local unprivileged user can exploit this flaw to cause system\nunstability and denial of services. (CVE-2012-4398)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-345.47","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-345-ec2","version":"2.6.32-345.47","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-345.47"}]},"type":"USN","cves_ids":["CVE-2011-4347","CVE-2012-0045","CVE-2012-1090","CVE-2012-1097","CVE-2012-4398"]},{"id":"USN-1458-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2012-05-31T21:47:52.279800","description":"A flaw was found in the Linux's kernels ext4 file system when mounted with\na journal. A local, unprivileged user could exploit this flaw to cause a\ndenial of service. (CVE-2011-4086)\n\nA flaw was discovered in the Linux kernel's cifs file system. An\nunprivileged local user could exploit this flaw to crash the system leading\nto a denial of service. (CVE-2012-1090)\n\nH. Peter Anvin reported a flaw in the Linux kernel that could crash the\nsystem. A local user could exploit this flaw to crash the system.\n(CVE-2012-1097)\n\nA flaw was discovered in the Linux kernel's cgroups subset. A local\nattacker could use this flaw to crash the system. (CVE-2012-1146)\n\nA flaw was found in the Linux kernel's ext4 file system when mounting a\ncorrupt filesystem. A user-assisted remote attacker could exploit this flaw\nto cause a denial of service. (CVE-2012-2100)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.24","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.24"}]},"type":"USN","cves_ids":["CVE-2011-4086","CVE-2012-1090","CVE-2012-1097","CVE-2012-1146","CVE-2012-2100"]}]},{"id":"CVE-2012-0868","published":"2012-02-28T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18,\n8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows\nuser-assisted remote attackers to execute arbitrary SQL commands via a\ncrafted file containing object names with newlines, which are inserted into\nan SQL script that is used when the database is restored.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.postgresql.org/support/security/","https://ubuntu.com/security/notices/USN-1378-1","https://www.cve.org/CVERecord?id=CVE-2012-0868"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/941912"],"patches":{"postgresql-9.1":[],"postgresql-8.4":[],"postgresql-8.3":[],"postgresql-8.2":[]},"tags":{},"packages":[{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"hardy","status":"released","description":"8.3.18-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.3.18","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.4.11-0ubuntu0.10.04","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.4.11-0ubuntu0.10.10","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.4.11-0ubuntu0.11.04","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"8.4.11-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.11","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"9.1.3-0ubuntu0.11.10","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.1.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1378-1"],"notices":[{"id":"USN-1378-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n\nThis update uses a new upstream release, which includes additional bug\nfixes.\n","references":[],"published":"2012-02-28T16:31:57.924925","description":"It was discovered that PostgreSQL incorrectly checked permissions on\nfunctions called by a trigger. An attacker could attach a trigger to a\ntable they owned and possibly escalate privileges. (CVE-2012-0866)\n\nIt was discovered that PostgreSQL incorrectly truncated SSL certificate\nname checks to 32 characters. If a host name was exactly 32 characters,\nthis issue could be exploited by an attacker to spoof the SSL certificate.\nThis issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 and\nUbuntu 11.10. (CVE-2012-0867)\n\nIt was discovered that the PostgreSQL pg_dump utility incorrectly filtered\nline breaks in object names. An attacker could create object names that\nexecute arbitrary SQL commands when a dump script is reloaded.\n(CVE-2012-0868)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"postgresql-8.3","version":"8.3.18-0ubuntu0.8.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.3","version":"8.3.18-0ubuntu0.8.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.18-0ubuntu0.8.04"}],"lucid":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.10.04"}],"maverick":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.10.10"}],"natty":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.11.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.11.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.11.04"}],"oneiric":[{"name":"postgresql-9.1","version":"9.1.3-0ubuntu0.11.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.3-0ubuntu0.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.3-0ubuntu0.11.10"}]},"type":"USN","cves_ids":["CVE-2012-0867","CVE-2012-0866","CVE-2012-0868"]}]},{"id":"CVE-2012-0867","published":"2012-02-28T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3\ntruncates the common name to only 32 characters when verifying SSL\ncertificates, which allows remote attackers to spoof connections when the\nhost name is exactly 32 characters.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"8.3 is not affected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.postgresql.org/support/security/","https://ubuntu.com/security/notices/USN-1378-1","https://www.cve.org/CVERecord?id=CVE-2012-0867"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/941912"],"patches":{"postgresql-9.1":[],"postgresql-8.4":[],"postgresql-8.3":[],"postgresql-8.2":[]},"tags":{},"packages":[{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.4.11-0ubuntu0.10.04","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.4.11-0ubuntu0.10.10","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.4.11-0ubuntu0.11.04","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"8.4.11-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.11","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"9.1.3-0ubuntu0.11.10","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.1.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1378-1"],"notices":[{"id":"USN-1378-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n\nThis update uses a new upstream release, which includes additional bug\nfixes.\n","references":[],"published":"2012-02-28T16:31:57.924925","description":"It was discovered that PostgreSQL incorrectly checked permissions on\nfunctions called by a trigger. An attacker could attach a trigger to a\ntable they owned and possibly escalate privileges. (CVE-2012-0866)\n\nIt was discovered that PostgreSQL incorrectly truncated SSL certificate\nname checks to 32 characters. If a host name was exactly 32 characters,\nthis issue could be exploited by an attacker to spoof the SSL certificate.\nThis issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 and\nUbuntu 11.10. (CVE-2012-0867)\n\nIt was discovered that the PostgreSQL pg_dump utility incorrectly filtered\nline breaks in object names. An attacker could create object names that\nexecute arbitrary SQL commands when a dump script is reloaded.\n(CVE-2012-0868)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"postgresql-8.3","version":"8.3.18-0ubuntu0.8.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.3","version":"8.3.18-0ubuntu0.8.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.18-0ubuntu0.8.04"}],"lucid":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.10.04"}],"maverick":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.10.10"}],"natty":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.11.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.11.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.11.04"}],"oneiric":[{"name":"postgresql-9.1","version":"9.1.3-0ubuntu0.11.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.3-0ubuntu0.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.3-0ubuntu0.11.10"}]},"type":"USN","cves_ids":["CVE-2012-0867","CVE-2012-0866","CVE-2012-0868"]}]},{"id":"CVE-2012-0866","published":"2012-02-28T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11,\n9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the\nexecute permission for trigger functions marked SECURITY DEFINER, which\nallows remote authenticated users to execute otherwise restricted triggers\non arbitrary data by installing the trigger on an attacker-owned table.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.postgresql.org/support/security/","https://ubuntu.com/security/notices/USN-1378-1","https://www.cve.org/CVERecord?id=CVE-2012-0866"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/941912"],"patches":{"postgresql-9.1":[],"postgresql-8.4":[],"postgresql-8.3":[],"postgresql-8.2":[]},"tags":{},"packages":[{"name":"postgresql-8.2","source":"https://ubuntu.com/security/cve?package=postgresql-8.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.2","debian":"https://tracker.debian.org/pkg/postgresql-8.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.3","source":"https://ubuntu.com/security/cve?package=postgresql-8.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.3","debian":"https://tracker.debian.org/pkg/postgresql-8.3","statuses":[{"release_codename":"hardy","status":"released","description":"8.3.18-0ubuntu0.8.04","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.3.18","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-8.4","source":"https://ubuntu.com/security/cve?package=postgresql-8.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-8.4","debian":"https://tracker.debian.org/pkg/postgresql-8.4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"8.4.11-0ubuntu0.10.04","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"8.4.11-0ubuntu0.10.10","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"8.4.11-0ubuntu0.11.04","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"8.4.11-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.11","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"9.1.3-0ubuntu0.11.10","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"9.1.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.1.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-1378-1"],"notices":[{"id":"USN-1378-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"In general, a standard system update will make all the necessary changes.\n\nThis update uses a new upstream release, which includes additional bug\nfixes.\n","references":[],"published":"2012-02-28T16:31:57.924925","description":"It was discovered that PostgreSQL incorrectly checked permissions on\nfunctions called by a trigger. An attacker could attach a trigger to a\ntable they owned and possibly escalate privileges. (CVE-2012-0866)\n\nIt was discovered that PostgreSQL incorrectly truncated SSL certificate\nname checks to 32 characters. If a host name was exactly 32 characters,\nthis issue could be exploited by an attacker to spoof the SSL certificate.\nThis issue affected Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04 and\nUbuntu 11.10. (CVE-2012-0867)\n\nIt was discovered that the PostgreSQL pg_dump utility incorrectly filtered\nline breaks in object names. An attacker could create object names that\nexecute arbitrary SQL commands when a dump script is reloaded.\n(CVE-2012-0868)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"postgresql-8.3","version":"8.3.18-0ubuntu0.8.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.3","version":"8.3.18-0ubuntu0.8.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.3/8.3.18-0ubuntu0.8.04"}],"lucid":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.10.04"}],"maverick":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.10.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.10.10"}],"natty":[{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.11.04","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-8.4","version":"8.4.11-0ubuntu0.11.04","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4","version_link":"https://launchpad.net/ubuntu/+source/postgresql-8.4/8.4.11-0ubuntu0.11.04"}],"oneiric":[{"name":"postgresql-9.1","version":"9.1.3-0ubuntu0.11.10","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-9.1","version":"9.1.3-0ubuntu0.11.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.1/9.1.3-0ubuntu0.11.10"}]},"type":"USN","cves_ids":["CVE-2012-0867","CVE-2012-0866","CVE-2012-0868"]}]},{"id":"CVE-2012-0453","published":"2012-02-25T04:21:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla\n4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows\nremote attackers to hijack the authentication of arbitrary users for\nrequests that modify the product's installation via the XML-RPC API.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2012-0453"],"bugs":[""],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.6.3.0-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"3.6.2.0-4.5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0507","published":"2012-02-24T00:00:00","updated_at":"2025-08-25T20:25:06.068622+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0\nUpdate 33 and earlier allows remote attackers to affect confidentiality,\nintegrity, and availability via unknown vectors related to Concurrency.\nNOTE: the previous information was obtained from the February 2012 Oracle\nCPU. Oracle has not commented on claims from a downstream vendor and third\nparty researchers that this issue occurs because the AtomicReferenceArray\nclass implementation does not ensure that the array is of the Object[]\ntype, which allows attackers to cause a denial of service (JVM crash) or\nbypass Java sandbox restrictions. NOTE: this issue was originally mapped\nto CVE-2011-3571, but that identifier was already assigned to a different\nissue.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in natty+, NetX and the plugin moved to the icedtea-web package"},{"author":"sbeattie","note":"initially, oracle misidentified this as CVE-2011-3571;\nchangelogs refer to that CVE instead of this one."}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1373-1","https://ubuntu.com/security/notices/USN-1373-2","https://www.cve.org/CVERecord?id=CVE-2012-0507","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[],"icedtea-web":[],"openjdk-7":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b20-1.9.13-0ubuntu1~10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6b20-1.9.13-0ubuntu1~10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6b22-1.10.6-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b23~pre11-0ubuntu1.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"6b24-1.11.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"6b24-1.11.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b18-1.8.13-0ubuntu1~10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"6b18-1.8.13-0ubuntu1~10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"6b18-1.8.13-0ubuntu1~11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u9-2.3.3-0ubuntu1~11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"7~u3-2.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"7~u3-2.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1373-1","USN-1373-2"],"notices":[{"id":"USN-1373-1","title":"OpenJDK 6 vulnerabilities","summary":"Multiple OpenJDK 6 vulnerabilities have been fixed.\n","instructions":"After a standard system update you need to restart any Java applications\nor applets to make all the necessary changes.\n","references":[],"published":"2012-02-24T10:35:32.518143","description":"It was discovered that the Java HttpServer class did not limit the\nnumber of headers read from a HTTP request. A remote attacker could\ncause a denial of service by sending special requests that trigger\nhash collisions predictably. (CVE-2011-5035)\n\nATTENTION: this update changes previous Java HttpServer class behavior\nby limiting the number of request headers to 200. This may be increased\nby adjusting the sun.net.httpserver.maxReqHeaders property.\n\nIt was discovered that the Java Sound component did not properly\ncheck buffer boundaries. A remote attacker could use this to cause\na denial of service or view confidential data. (CVE-2011-3563)\n\nIt was discovered that the Java2D implementation does not properly\ncheck graphics rendering objects before passing them to the native\nrenderer. A remote attacker could use this to cause a denial of\nservice or to bypass Java sandbox restrictions. (CVE-2012-0497)\n\nIt was discovered that an off-by-one error exists in the Java ZIP\nfile processing code. An attacker could us this to cause a denial of\nservice through a maliciously crafted ZIP file. (CVE-2012-0501)\n\nIt was discovered that the Java AWT KeyboardFocusManager did not\nproperly enforce keyboard focus security policy. A remote attacker\ncould use this with an untrusted application or applet to grab keyboard\nfocus and possibly expose confidential data. (CVE-2012-0502)\n\nIt was discovered that the Java TimeZone class did not properly enforce\nsecurity policy around setting the default time zone. A remote attacker\ncould use this with an untrusted application or applet to set a new\ndefault time zone and bypass Java sandbox restrictions. (CVE-2012-0503)\n\nIt was discovered the Java ObjectStreamClass did not throw\nan accurately identifiable exception when a deserialization\nfailure occurred. A remote attacker could use this with\nan untrusted application or applet to bypass Java sandbox\nrestrictions. (CVE-2012-0505)\n\nIt was discovered that the Java CORBA implementation did not properly\nprotect repository identifiers on certain CORBA objects. A remote\nattacker could use this to corrupt object data. (CVE-2012-0506)\n\nIt was discovered that the Java AtomicReferenceArray class\nimplementation did not properly check if an array was of\nthe expected Object[] type. A remote attacker could use this\nwith a malicious application or applet to bypass Java sandbox\nrestrictions. (CVE-2012-0507)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"openjdk-6","version":"6b20-1.9.13-0ubuntu1~10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b20-1.9.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.04.1"},{"name":"openjdk-6-jre-lib","version":"6b20-1.9.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b20-1.9.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.04.1"},{"name":"openjdk-6-jre","version":"6b20-1.9.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b20-1.9.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.04.1"}],"maverick":[{"name":"openjdk-6","version":"6b20-1.9.13-0ubuntu1~10.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b20-1.9.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.10.1"},{"name":"openjdk-6-jre-lib","version":"6b20-1.9.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.10.1"},{"name":"icedtea-6-jre-cacao","version":"6b20-1.9.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.10.1"},{"name":"openjdk-6-jre","version":"6b20-1.9.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.10.1"},{"name":"openjdk-6-jre-zero","version":"6b20-1.9.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b20-1.9.13-0ubuntu1~10.10.1"}],"natty":[{"name":"openjdk-6","version":"6b22-1.10.6-0ubuntu1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b22-1.10.6-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.6-0ubuntu1"},{"name":"icedtea-6-jre-jamvm","version":"6b22-1.10.6-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.6-0ubuntu1"},{"name":"openjdk-6-jre","version":"6b22-1.10.6-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.6-0ubuntu1"},{"name":"openjdk-6-jre-headless","version":"6b22-1.10.6-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.6-0ubuntu1"},{"name":"openjdk-6-jre-zero","version":"6b22-1.10.6-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.6-0ubuntu1"},{"name":"openjdk-6-jre-lib","version":"6b22-1.10.6-0ubuntu1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b22-1.10.6-0ubuntu1"}],"oneiric":[{"name":"openjdk-6","version":"6b23~pre11-0ubuntu1.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b23~pre11-0ubuntu1.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b23~pre11-0ubuntu1.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10.2"},{"name":"openjdk-6-jre","version":"6b23~pre11-0ubuntu1.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b23~pre11-0ubuntu1.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b23~pre11-0ubuntu1.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b23~pre11-0ubuntu1.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b23~pre11-0ubuntu1.11.10.2"}]},"type":"USN","cves_ids":["CVE-2011-3563","CVE-2012-0507","CVE-2011-5035","CVE-2012-0497","CVE-2012-0501","CVE-2012-0502","CVE-2012-0503","CVE-2012-0505","CVE-2012-0506"]},{"id":"USN-1373-2","title":"OpenJDK 6 (ARM) vulnerabilities","summary":"Multiple vulnerabilities in OpenJDK 6 for the ARM architecture have\nbeen fixed.\n","instructions":"After a standard system update you need to restart any Java applications\nor applets to make all the necessary changes.\n","references":[],"published":"2012-03-01T09:07:31.675963","description":"USN 1373-1 fixed vulnerabilities in OpenJDK 6 in Ubuntu 10.04 LTS,\nUbuntu 10.10 and Ubuntu 11.04 for all architectures except for ARM\n(armel). This provides the corresponding OpenJDK 6 update for use\nwith the ARM (armel) architecture in Ubuntu 10.04 LTS, Ubuntu 10.10\nand Ubuntu 11.04.\n\nOriginal advisory details:\n\n It was discovered that the Java HttpServer class did not limit the\n number of headers read from a HTTP request. A remote attacker could\n cause a denial of service by sending special requests that trigger\n hash collisions predictably. (CVE-2011-5035)\n \n ATTENTION: this update changes previous Java HttpServer class behavior\n by limiting the number of request headers to 200. This may be increased\n by adjusting the sun.net.httpserver.maxReqHeaders property.\n \n It was discovered that the Java Sound component did not properly\n check buffer boundaries. A remote attacker could use this to cause\n a denial of service or view confidential data. (CVE-2011-3563)\n \n It was discovered that the Java2D implementation does not properly\n check graphics rendering objects before passing them to the native\n renderer. A remote attacker could use this to cause a denial of\n service or to bypass Java sandbox restrictions. (CVE-2012-0497)\n \n It was discovered that an off-by-one error exists in the Java ZIP\n file processing code. An attacker could us this to cause a denial of\n service through a maliciously crafted ZIP file. (CVE-2012-0501)\n \n It was discovered that the Java AWT KeyboardFocusManager did not\n properly enforce keyboard focus security policy. A remote attacker\n could use this with an untrusted application or applet to grab keyboard\n focus and possibly expose confidential data. (CVE-2012-0502)\n \n It was discovered that the Java TimeZone class did not properly enforce\n security policy around setting the default time zone. A remote attacker\n could use this with an untrusted application or applet to set a new\n default time zone and bypass Java sandbox restrictions. (CVE-2012-0503)\n \n It was discovered the Java ObjectStreamClass did not throw\n an accurately identifiable exception when a deserialization\n failure occurred. A remote attacker could use this with\n an untrusted application or applet to bypass Java sandbox\n restrictions. (CVE-2012-0505)\n \n It was discovered that the Java CORBA implementation did not properly\n protect repository identifiers on certain CORBA objects. A remote\n attacker could use this to corrupt object data. (CVE-2012-0506)\n \n It was discovered that the Java AtomicReferenceArray class\n implementation did not properly check if an array was of\n the expected Object[] type. A remote attacker could use this\n with a malicious application or applet to bypass Java sandbox\n restrictions. (CVE-2012-0507)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"openjdk-6b18","version":"6b18-1.8.13-0ubuntu1~10.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b18-1.8.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b18-1.8.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.04.1"},{"name":"openjdk-6-jre","version":"6b18-1.8.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.04.1"},{"name":"openjdk-6-jre-zero","version":"6b18-1.8.13-0ubuntu1~10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.04.1"}],"maverick":[{"name":"openjdk-6b18","version":"6b18-1.8.13-0ubuntu1~10.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b18-1.8.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.10.1"},{"name":"icedtea-6-jre-cacao","version":"6b18-1.8.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.10.1"},{"name":"openjdk-6-jre","version":"6b18-1.8.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.10.1"},{"name":"openjdk-6-jre-zero","version":"6b18-1.8.13-0ubuntu1~10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~10.10.1"}],"natty":[{"name":"openjdk-6b18","version":"6b18-1.8.13-0ubuntu1~11.04.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b18-1.8.13-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~11.04.1"},{"name":"icedtea-6-jre-cacao","version":"6b18-1.8.13-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~11.04.1"},{"name":"openjdk-6-jre","version":"6b18-1.8.13-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~11.04.1"},{"name":"icedtea-6-jre-jamvm","version":"6b18-1.8.13-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~11.04.1"},{"name":"openjdk-6-jre-zero","version":"6b18-1.8.13-0ubuntu1~11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6b18/6b18-1.8.13-0ubuntu1~11.04.1"}]},"type":"USN","cves_ids":["CVE-2012-0501","CVE-2012-0497","CVE-2011-5035","CVE-2012-0503","CVE-2011-3563","CVE-2012-0507","CVE-2012-0502","CVE-2012-0505","CVE-2012-0506"]}]},{"id":"CVE-2012-0823","published":"2012-02-23T20:07:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nVP8 Codec SDK (libvpx) before 1.0.0 \"Duclair\" allows remote attackers to\ncause a denial of service (application crash) via (1) unspecified \"corrupt\ninput\" or (2) by \"starting decoding from a P-frame,\" which triggers an\nout-of-bounds read, related to \"the clamping of motion vectors in SPLITMV\nblocks\".","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Upstream changelog indicates this was introduced in 0.9.7"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://blog.webmproject.org/2012/01/vp8-codec-sdk-duclair-released.html","http://seclists.org/oss-sec/2012/q1/315","https://www.cve.org/CVERecord?id=CVE-2012-0823"],"bugs":[""],"patches":{"libvpx":[]},"tags":{},"packages":[{"name":"libvpx","source":"https://ubuntu.com/security/cve?package=libvpx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvpx","debian":"https://tracker.debian.org/pkg/libvpx","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.9.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"1.0.0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-1054","published":"2012-02-23T05:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPuppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise\n(PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login\nfile with the k5login resource type, allows local users to gain privileges\nvia a symlink attack on .k5login.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://puppetlabs.com/security/cve/cve-2012-1054/","https://ubuntu.com/security/notices/USN-1372-1","https://www.cve.org/CVERecord?id=CVE-2012-1054"],"bugs":[""],"patches":{"puppet":[]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.25.4-2ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.1-0ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.4-2ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.7.1-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.14, 2.7.11-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1372-1"],"notices":[{"id":"USN-1372-1","title":"Puppet vulnerabilities","summary":"Puppet could be made to overwrite files and run programs with administrator\nprivileges.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-23T13:29:25.169809","description":"It was discovered that Puppet did not drop privileges when executing\ncommands as different users. If an attacker had control of the execution\nmanifests or the executed command, this could be used to execute code with\nelevated group permissions (typically root). (CVE-2012-1053)\n\nIt was discovered that Puppet unsafely opened files when the k5login type\nis used to manage files. A local attacker could exploit this to overwrite\narbitrary files and escalate privileges. (CVE-2012-1054)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"puppet","version":"0.25.4-2ubuntu6.6","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"0.25.4-2ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/0.25.4-2ubuntu6.6"}],"maverick":[{"name":"puppet","version":"2.6.1-0ubuntu2.6","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.6.1-0ubuntu2.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.6.1-0ubuntu2.6"}],"natty":[{"name":"puppet","version":"2.6.4-2ubuntu2.8","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.6.4-2ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.6.4-2ubuntu2.8"}],"oneiric":[{"name":"puppet","version":"2.7.1-1ubuntu3.5","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.1-1ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.1-1ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2012-1053","CVE-2012-1054"]}]},{"id":"CVE-2012-1053","published":"2012-02-23T05:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb)\nin Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet\nEnterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly\nmanage group privileges, which allows local users to gain privileges via\nvectors related to (1) the change_user not dropping supplementary groups in\ncertain conditions, (2) changes to the eguid without associated changes to\nthe egid, or (3) the addition of the real gid to supplementary groups.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://puppetlabs.com/security/cve/cve-2012-1053/","https://ubuntu.com/security/notices/USN-1372-1","https://www.cve.org/CVERecord?id=CVE-2012-1053"],"bugs":[""],"patches":{"puppet":[]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"0.25.4-2ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.1-0ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.4-2ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"2.7.1-1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.14, 2.7.11-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1372-1"],"notices":[{"id":"USN-1372-1","title":"Puppet vulnerabilities","summary":"Puppet could be made to overwrite files and run programs with administrator\nprivileges.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-23T13:29:25.169809","description":"It was discovered that Puppet did not drop privileges when executing\ncommands as different users. If an attacker had control of the execution\nmanifests or the executed command, this could be used to execute code with\nelevated group permissions (typically root). (CVE-2012-1053)\n\nIt was discovered that Puppet unsafely opened files when the k5login type\nis used to manage files. A local attacker could exploit this to overwrite\narbitrary files and escalate privileges. (CVE-2012-1054)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"puppet","version":"0.25.4-2ubuntu6.6","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"0.25.4-2ubuntu6.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/0.25.4-2ubuntu6.6"}],"maverick":[{"name":"puppet","version":"2.6.1-0ubuntu2.6","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.6.1-0ubuntu2.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.6.1-0ubuntu2.6"}],"natty":[{"name":"puppet","version":"2.6.4-2ubuntu2.8","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.6.4-2ubuntu2.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.6.4-2ubuntu2.8"}],"oneiric":[{"name":"puppet","version":"2.7.1-1ubuntu3.5","description":"Centralized configuration management","is_source":true},{"name":"puppet-common","version":"2.7.1-1ubuntu3.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/2.7.1-1ubuntu3.5"}]},"type":"USN","cves_ids":["CVE-2012-1053","CVE-2012-1054"]}]},{"id":"CVE-2012-0879","published":"2012-02-23T00:00:00","updated_at":"2026-07-04T07:32:22.703015+00:00","description":"\nThe I/O implementation for block devices in the Linux kernel before 2.6.33\ndoes not properly handle the CLONE_IO feature, which allows local users to\ncause a denial of service (I/O instability) by starting multiple processes\nthat share an I/O context.","ubuntu_description":"\nLouis Rilling discovered a flaw in Linux kernel's clone command when\nCLONE_IO is specified. An unprivileged local user could exploit this to\ncause a denial of service.","notes":[{"author":"jdstrand","note":"per Petr Matousek, \"Looks like it got fixed in Linux kernel 2.6.33(-rc1)\""},{"author":"apw","note":"CLONE_IO was introduced by the commit below, the bug cannot have\nexisted before then:\nfadad878cc0640cc9cd5569998bf54b693f7b38b"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2012/02/23/5","http://comments.gmane.org/gmane.linux.kernel/922519","https://ubuntu.com/security/notices/USN-1389-1","https://ubuntu.com/security/notices/USN-1411-1","https://ubuntu.com/security/notices/USN-1408-1","https://ubuntu.com/security/notices/USN-1410-1","https://www.cve.org/CVERecord?id=CVE-2012-0879"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=796829","https://launchpad.net/bugs/940743"],"patches":{"linux":["break-fix: fadad878cc0640cc9cd5569998bf54b693f7b38b 61cc74fbb87af6aa551a06a370590c9bc07e29d9","break-fix: fadad878cc0640cc9cd5569998bf54b693f7b38b b69f2292063d2caf37ca9aec7d63ded203701bf3"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-40.87","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.37-2.9","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.39-0.0","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.1.0-1.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.1.0-1.0","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.1.0-1.0","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.2.0-1600.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.2.0-1602.5","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-344.46","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-612.34","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"2.6.38-1.27~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.0.0-5.6~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"2.6.38-1201.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"2.6.38-1309.13","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"3.0.0-1401.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.33~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1410-1","USN-1411-1","USN-1408-1"],"notices":[{"id":"USN-1410-1","title":"Linux kernel (EC2) vulnerability","summary":"The system could be made to crash under certain conditions.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-27T11:42:51.635687","description":"Louis Rilling discovered a flaw in Linux kernel's clone command when\nCLONE_IO is specified. An unprivileged local user could exploit this to\ncause a denial of service.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-344.46","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-344-ec2","version":"2.6.32-344.46","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-344.46"}]},"type":"USN","cves_ids":["CVE-2012-0879"]},{"id":"USN-1411-1","title":"Linux kernel vulnerability","summary":"The system could be made to crash under certain conditions.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-27T11:48:05.780834","description":"\nLouis Rilling discovered a flaw in Linux kernel's clone command when\nCLONE_IO is specified. An unprivileged local user could exploit this to\ncause a denial of service.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-40.87","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-40-generic","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-sparc64-smp","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-preempt","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-powerpc-smp","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-versatile","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-powerpc64-smp","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-virtual","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-generic-pae","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-lpia","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-powerpc","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-sparc64","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-server","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-ia64","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"},{"name":"linux-image-2.6.32-40-386","version":"2.6.32-40.87","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-40.87"}]},"type":"USN","cves_ids":["CVE-2012-0879"]},{"id":"USN-1408-1","title":"Linux kernel (FSL-IMX51) vulnerability","summary":"The system could be made to crash under certain conditions.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2012-03-27T11:31:18.047727","description":"Louis Rilling discovered a flaw in Linux kernel's clone command when\nCLONE_IO is specified. An unprivileged local user could exploit this to\ncause a denial of service.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-612.34","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-612-imx51","version":"2.6.31-612.34","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-612.34"}]},"type":"USN","cves_ids":["CVE-2012-0879"]}]},{"id":"CVE-2012-0870","published":"2012-02-23T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nHeap-based buffer overflow in process.c in smbd in Samba 3.0, as used in\nthe file-sharing service on the BlackBerry PlayBook tablet before\n2.0.0.7971 and other products, allows remote attackers to cause a denial of\nservice (daemon crash) or possibly execute arbitrary code via a Batched\n(aka AndX) request that triggers infinite recursion.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects samba < 3.4.0"}],"codename":null,"priority":"high","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://btsc.webapps.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB29565","http://www.securityfocus.com/bid/52103","http://www.samba.org/samba/security/CVE-2012-0870.html","https://ubuntu.com/security/notices/USN-1374-1","https://www.cve.org/CVERecord?id=CVE-2012-0870"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=795509","https://access.redhat.com/security/cve/CVE-2012-0870"],"patches":{"samba":["vendor: https://rhn.redhat.com/errata/RHSA-2012-0332.html","upstream: http://www.samba.org/samba/ftp/patches/security/samba-3.0-CVE-2012-0870.patch"]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"hardy","status":"released","description":"3.0.28a-1ubuntu4.17","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:3.4.0~pre1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-1374-1"],"notices":[{"id":"USN-1374-1","title":"Samba vulnerability","summary":"Samba could be made to crash or run programs if it received specially\ncrafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-24T15:06:49.836924","description":"Andy Davis discovered that Samba incorrectly handled certain AndX offsets.\nA remote attacker could send a specially crafted request to the server and\ncause a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"hardy":[{"name":"samba","version":"3.0.28a-1ubuntu4.17","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"3.0.28a-1ubuntu4.17","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.17"}]},"type":"USN","cves_ids":["CVE-2012-0870"]}]}],"offset":70000,"limit":20,"total_results":79316}