{"cves":[{"id":"CVE-2012-1050","published":"2012-02-13T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDirectory traversal vulnerability in Mathopd 1.4.x and 1.5.x before 1.5p7,\nwhen configured with the * construct for mass virtual hosting, allows\nremote attackers to read arbitrary files via a crafted Host header.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mail-archive.com/mathopd%40mathopd.org/msg00392.html","https://www.cve.org/CVERecord?id=CVE-2012-1050"],"bugs":[""],"patches":{"mathopd":[]},"tags":{},"packages":[{"name":"mathopd","source":"https://ubuntu.com/security/cve?package=mathopd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mathopd","debian":"https://tracker.debian.org/pkg/mathopd","statuses":[{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0452","published":"2012-02-13T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1,\nThunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers\nto cause a denial of service (application crash) or possibly execute\narbitrary code via vectors that trigger failure of an\nnsXBLDocumentInfo::ReadPrototypeBindings function call, related to the\ncycle collector's access to a hash table containing a stale XBL binding.","ubuntu_description":"","notes":[{"author":"micahg","note":"did not affect Firefox 9, Thunderbird 9, Seamonkey 2.6 or earlier"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mozilla.org/security/announce/2012/mfsa2012-10.html","https://ubuntu.com/security/notices/USN-1360-1","https://ubuntu.com/security/notices/USN-1369-1","https://www.cve.org/CVERecord?id=CVE-2012-0452"],"bugs":[""],"patches":{"firefox":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"10.0.1+build1-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"10.0.1+build1-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"10.0.1+build1-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"10.0.1+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"11.0~b2+build1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.1","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.1","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"3.1.x","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"3.1.x","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.1.x","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"10.0.1+build1-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"12.0.1+build1-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.0.1","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1360-1","USN-1369-1"],"notices":[{"id":"USN-1360-1","title":"Firefox vulnerability","summary":"A security vulnerability has been fixed in Firefox.\n","instructions":"After a standard system update you need to restart Firefox to make all the\nnecessary changes.\n","references":["https://launchpad.net/bugs/929833"],"published":"2012-02-13T16:57:56.582782","description":"Andrew McCreight and Olli Pettay discovered a use-after-free vulnerability\nin the XBL bindings. An attacker could exploit this to cause a denial of\nservice via application crash, or potentially execute code with the\nprivileges of the user invoking Firefox. (CVE-2012-0452)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"firefox","version":"10.0.1+build1-0ubuntu0.10.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"10.0.1+build1-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/10.0.1+build1-0ubuntu0.10.04.1"}],"maverick":[{"name":"firefox","version":"10.0.1+build1-0ubuntu0.10.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"10.0.1+build1-0ubuntu0.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/10.0.1+build1-0ubuntu0.10.10.1"}],"natty":[{"name":"firefox","version":"10.0.1+build1-0ubuntu0.11.04.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"10.0.1+build1-0ubuntu0.11.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/10.0.1+build1-0ubuntu0.11.04.1"}],"oneiric":[{"name":"firefox","version":"10.0.1+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source web browser","is_source":true},{"name":"firefox","version":"10.0.1+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/10.0.1+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-0452"]},{"id":"USN-1369-1","title":"Thunderbird vulnerabilities","summary":"Several security issues were fixed in Thunderbird.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":["https://launchpad.net/bugs/933382","https://launchpad.net/bugs/923372","https://launchpad.net/bugs/929964"],"published":"2012-02-17T23:11:06.608470","description":"Nicolas Gregoire and Aki Helin discovered that when processing a malformed\nembedded XSLT stylesheet, Thunderbird can crash due to memory corruption.\nIf the user were tricked into opening a specially crafted page, an attacker\ncould exploit this to cause a denial of service via application crash, or\npotentially execute code with the privileges of the user invoking\nThunderbird. (CVE-2012-0449)\n\nIt was discovered that memory corruption could occur during the decoding of\nOgg Vorbis files. If the user were tricked into opening a specially crafted\nfile, an attacker could exploit this to cause a denial of service via\napplication crash, or potentially execute code with the privileges of the\nuser invoking Thunderbird. (CVE-2012-0444)\n\nTim Abraldes discovered that when encoding certain image types the\nresulting data was always a fixed size. There is the possibility of\nsensitive data from uninitialized memory being appended to these images.\n(CVE-2012-0447)\n\nIt was discovered that Thunderbird did not properly perform XPConnect\nsecurity checks. An attacker could exploit this to conduct cross-site\nscripting (XSS) attacks through web pages and Thunderbird extensions. With\ncross-site scripting vulnerabilities, if a user were tricked into viewing a\nspecially crafted page, a remote attacker could exploit this to modify the\ncontents, or steal confidential data, within the same domain.\n(CVE-2012-0446)\n\nIt was discovered that Thunderbird did not properly handle node removal in\nthe DOM. If the user were tricked into opening a specially crafted page, an\nattacker could exploit this to cause a denial of service via application\ncrash, or potentially execute code with the privileges of the user invoking\nThunderbird. (CVE-2011-3659)\n\nAlex Dvorov discovered that Thunderbird did not properly handle sub-frames\nin form submissions. An attacker could exploit this to conduct phishing\nattacks using HTML5 frames. (CVE-2012-0445)\n\nBen Hawkes, Christian Holler, Honza Bombas, Jason Orendorff, Jesse\nRuderman, Jan Odvarko, Peter Van Der Beken, Bob Clary, and Bill McCloskey\ndiscovered memory safety issues affecting Thunderbird. If the user were\ntricked into opening a specially crafted page, an attacker could exploit\nthese to cause a denial of service via application crash, or potentially\nexecute code with the privileges of the user invoking Thunderbird.\n(CVE-2012-0442, CVE-2012-0443)\n\nAndrew McCreight and Olli Pettay discovered a use-after-free vulnerability\nin the XBL bindings. An attacker could exploit this to cause a denial of\nservice via application crash, or potentially execute code with the\nprivileges of the user invoking Thunderbird. (CVE-2012-0452)\n\nJueri Aedla discovered that libpng, which is in Thunderbird, did not\nproperly verify the size used when allocating memory during chunk\ndecompression. If a user or automated system using libpng were tricked into\nopening a specially crafted image, an attacker could exploit this to cause\na denial of service or execute code with the privileges of the user\ninvoking the program. (CVE-2011-3026)\n","is_hidden":false,"release_packages":{"oneiric":[{"name":"thunderbird","version":"10.0.2+build1-0ubuntu0.11.10.1","description":"Mozilla Open Source mail and newsgroup client","is_source":true},{"name":"thunderbird","version":"10.0.2+build1-0ubuntu0.11.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/10.0.2+build1-0ubuntu0.11.10.1"}]},"type":"USN","cves_ids":["CVE-2012-0452","CVE-2011-3659","CVE-2012-0442","CVE-2012-0443","CVE-2012-0444","CVE-2012-0445","CVE-2012-0446","CVE-2012-0447","CVE-2012-0449"]}]},{"id":"CVE-2012-0248","published":"2012-02-13T00:00:00","updated_at":"2025-08-25T20:24:16.032965+00:00","description":"\nImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial\nof service (infinite loop and hang) via a crafted image whose IFD contains\nIOP tags that all reference the beginning of the IDF.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"r6998 is the fix for CVE-2012-1186 which was assigned as an\nincomplete fix for this issue (see oss-sec for more information)."},{"author":"mdeslaur","note":"see fixes in CVE-2012-0247"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286","http://www.openwall.com/lists/oss-security/2012/03/19/5","https://ubuntu.com/security/notices/USN-1435-1","https://www.cve.org/CVERecord?id=CVE-2012-0248"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"7:6.5.7.8-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"7:6.6.2.6-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"8:6.6.0.4-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.7.5.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1435-1"],"notices":[{"id":"USN-1435-1","title":"ImageMagick vulnerabilities","summary":"ImageMagick could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-05-01T14:58:49.720152","description":"Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick\nincorrectly handled certain ResolutionUnit tags. If a user or automated\nsystem using ImageMagick were tricked into opening a specially crafted\nimage, an attacker could exploit this to cause a denial of service or\npossibly execute code with the privileges of the user invoking the program.\n(CVE-2012-0247, CVE-2012-1185)\n\nJoonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick\nincorrectly handled certain IFD structures. If a user or automated\nsystem using ImageMagick were tricked into opening a specially crafted\nimage, an attacker could exploit this to cause a denial of service.\n(CVE-2012-0248, CVE-2012-1186)\n\nAleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that\nImageMagick incorrectly handled certain JPEG EXIF tags. If a user or\nautomated system using ImageMagick were tricked into opening a specially\ncrafted image, an attacker could exploit this to cause a denial of service.\n(CVE-2012-0259)\n\nIt was discovered that ImageMagick incorrectly handled certain JPEG EXIF\ntags. If a user or automated system using ImageMagick were tricked into\nopening a specially crafted image, an attacker could exploit this to cause\na denial of service or possibly execute code with the privileges of the\nuser invoking the program. (CVE-2012-1610)\n\nAleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that\nImageMagick incorrectly handled certain TIFF EXIF tags. If a user or\nautomated system using ImageMagick were tricked into opening a specially\ncrafted image, an attacker could exploit this to cause a denial of service\nor possibly execute code with the privileges of the user invoking the\nprogram. (CVE-2012-1798)\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.1","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.1"},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.1"}],"lucid":[{"name":"imagemagick","version":"7:6.5.7.8-1ubuntu1.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"7:6.5.7.8-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.5.7.8-1ubuntu1.2"},{"name":"libmagick++2","version":"7:6.5.7.8-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.5.7.8-1ubuntu1.2"}],"natty":[{"name":"imagemagick","version":"7:6.6.2.6-1ubuntu4.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"7:6.6.2.6-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.6.2.6-1ubuntu4.1"},{"name":"libmagick++3","version":"7:6.6.2.6-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.6.2.6-1ubuntu4.1"}],"oneiric":[{"name":"imagemagick","version":"8:6.6.0.4-3ubuntu1.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.0.4-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.0.4-3ubuntu1.1"},{"name":"libmagick++3","version":"8:6.6.0.4-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.0.4-3ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2012-0247","CVE-2012-0248","CVE-2012-0259","CVE-2012-1185","CVE-2012-1186","CVE-2012-1610","CVE-2012-1798"]}]},{"id":"CVE-2012-0247","published":"2012-02-13T00:00:00","updated_at":"2025-08-25T20:24:16.032965+00:00","description":"\nImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial\nof service (memory corruption) and possibly execute arbitrary code via\ncrafted offset and count values in the ResolutionUnit tag in the EXIF IFD0\nof an image.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"I can't seem to reproduce this...seems to me gcc is doing the\nright thing when casting short to size_t"},{"author":"jdstrand","note":"r6998 is the fix for CVE-2012-1185 which was assigned as an\nincomplete fix for this issue (see oss-sec thread)."}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286","http://www.openwall.com/lists/oss-security/2012/03/19/5","https://ubuntu.com/security/notices/USN-1435-1","https://www.cve.org/CVERecord?id=CVE-2012-0247"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659339"],"patches":{"imagemagick":["upstream: http://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=20286","upstream: r6667, r6668, r6676, r6986, r6991, r6994, r6998","upstream: http://trac.imagemagick.org/changeset/6667","upstream: http://trac.imagemagick.org/changeset/6668","upstream: http://trac.imagemagick.org/changeset/6676","upstream: http://trac.imagemagick.org/changeset/6986","upstream: http://trac.imagemagick.org/changeset/6991","upstream: http://trac.imagemagick.org/changeset/6994","upstream: http://trac.imagemagick.org/changeset/6998/ImageMagick/branches/ImageMagick-6.7.5/magick/profile.c","upstream: http://trac.imagemagick.org/changeset/6998/ImageMagick/branches/ImageMagick-6.7.5/magick/property.c"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"7:6.5.7.8-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"7:6.6.2.6-1ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"8:6.6.0.4-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.7.5.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1435-1"],"notices":[{"id":"USN-1435-1","title":"ImageMagick vulnerabilities","summary":"ImageMagick could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-05-01T14:58:49.720152","description":"Joonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick\nincorrectly handled certain ResolutionUnit tags. If a user or automated\nsystem using ImageMagick were tricked into opening a specially crafted\nimage, an attacker could exploit this to cause a denial of service or\npossibly execute code with the privileges of the user invoking the program.\n(CVE-2012-0247, CVE-2012-1185)\n\nJoonas Kuorilehto and Aleksis Kauppinen discovered that ImageMagick\nincorrectly handled certain IFD structures. If a user or automated\nsystem using ImageMagick were tricked into opening a specially crafted\nimage, an attacker could exploit this to cause a denial of service.\n(CVE-2012-0248, CVE-2012-1186)\n\nAleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that\nImageMagick incorrectly handled certain JPEG EXIF tags. If a user or\nautomated system using ImageMagick were tricked into opening a specially\ncrafted image, an attacker could exploit this to cause a denial of service.\n(CVE-2012-0259)\n\nIt was discovered that ImageMagick incorrectly handled certain JPEG EXIF\ntags. If a user or automated system using ImageMagick were tricked into\nopening a specially crafted image, an attacker could exploit this to cause\na denial of service or possibly execute code with the privileges of the\nuser invoking the program. (CVE-2012-1610)\n\nAleksis Kauppinen, Joonas Kuorilehto and Tuomas Parttimaa discovered that\nImageMagick incorrectly handled certain TIFF EXIF tags. If a user or\nautomated system using ImageMagick were tricked into opening a specially\ncrafted image, an attacker could exploit this to cause a denial of service\nor possibly execute code with the privileges of the user invoking the\nprogram. (CVE-2012-1798)\n","is_hidden":false,"release_packages":{"precise":[{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.1","description":"Image manipulation programs and library","is_source":true},{"name":"libmagick++4","version":"8:6.6.9.7-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.1"},{"name":"imagemagick","version":"8:6.6.9.7-5ubuntu3.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.1"}],"lucid":[{"name":"imagemagick","version":"7:6.5.7.8-1ubuntu1.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"7:6.5.7.8-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.5.7.8-1ubuntu1.2"},{"name":"libmagick++2","version":"7:6.5.7.8-1ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.5.7.8-1ubuntu1.2"}],"natty":[{"name":"imagemagick","version":"7:6.6.2.6-1ubuntu4.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"7:6.6.2.6-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.6.2.6-1ubuntu4.1"},{"name":"libmagick++3","version":"7:6.6.2.6-1ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/7:6.6.2.6-1ubuntu4.1"}],"oneiric":[{"name":"imagemagick","version":"8:6.6.0.4-3ubuntu1.1","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.6.0.4-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.0.4-3ubuntu1.1"},{"name":"libmagick++3","version":"8:6.6.0.4-3ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.0.4-3ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2012-0247","CVE-2012-0248","CVE-2012-0259","CVE-2012-1185","CVE-2012-1186","CVE-2012-1610","CVE-2012-1798"]}]},{"id":"CVE-2012-0834","published":"2012-02-11T02:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in lib/QueryRender.php in\nphpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary\nweb script or HTML via the base parameter in a query_engine action to\ncmd.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://secunia.com/advisories/47852/","https://www.cve.org/CVERecord?id=CVE-2012-0834"],"bugs":["http://sourceforge.net/tracker/index.php?func=detail&aid=3477910&group_id=61828&atid=498546"],"patches":{"phpldapadmin":["upstream: http://phpldapadmin.git.sourceforge.net/git/gitweb.cgi?p=phpldapadmin/phpldapadmin;a=commit;h=7dc8d57d6952fe681cb9e8818df7f103220457bd"]},"tags":{},"packages":[{"name":"phpldapadmin","source":"https://ubuntu.com/security/cve?package=phpldapadmin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpldapadmin","debian":"https://tracker.debian.org/pkg/phpldapadmin","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.2.2-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.2-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.2.2-5.2ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.2.2-5ubuntu1.1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0840","published":"2012-02-10T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\ntables/apr_hash.c in the Apache Portable Runtime (APR) library through\n1.4.5 computes hash values without restricting the ability to trigger hash\ncollisions predictably, which allows context-dependent attackers to cause a\ndenial of service (CPU consumption) via crafted input to an application\nthat maintains a hash table.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"from oss-security: \"r1231605 and r1231858 cause massive\nregressions and test case failures in httpd.\" (These were\nsubsequently reverted)\nCVE was asked to be cancelled:\nhttp://www.mail-archive.com/dev%40apr.apache.org/msg24609.html\n\"After extensive consultation with the security projects of various\nAPR consumers, it's apparent that there are no actual\nvulnerabilities to be exploited here.\"\n\"These changes do not represent either a security DEFECT nor any\nactual security FIX. The APR Project dis-acknowledges the\nassignment of CVE-2012-0840 as erroneous, and invalid.\"\nDowngrading priority to \"low\"."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.mail-archive.com/dev%40apr.apache.org/msg24439.html","http://www.mail-archive.com/dev%40apr.apache.org/msg24473.html","https://www.cve.org/CVERecord?id=CVE-2012-0840"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-0840","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655435","https://bugs.launchpad.net/ubuntu/+source/apr/+bug/957727"],"patches":{"apr":["upstream: http://svn.apache.org/viewvc?view=revision&revision=1236970","upstream: http://svn.apache.org/viewvc?view=revision&revision=1237078","upstream: http://svn.apache.org/viewvc?view=revision&revision=1237507"]},"tags":{},"packages":[{"name":"apr","source":"https://ubuntu.com/security/cve?package=apr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apr","debian":"https://tracker.debian.org/pkg/apr","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.4.6-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.4.6-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.4.6-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.4.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.4.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"1.4.6-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"1.4.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3972","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe shader translator implementation in Google Chrome before 17.0.963.46\nallows remote attackers to cause a denial of service (out-of-bounds read)\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3972"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=110559"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3971","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 17.0.963.46 allows\nuser-assisted remote attackers to cause a denial of service or possibly\nhave unspecified other impact via vectors related to mousemove events.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3971"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=110374"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3969","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 17.0.963.46 allows\nremote attackers to cause a denial of service or possibly have unspecified\nother impact via vectors related to layout of SVG documents.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3969"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=110112"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3968","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 17.0.963.46 allows\nremote attackers to cause a denial of service or possibly have unspecified\nother impact via vectors involving Cascading Style Sheets (CSS) token\nsequences.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3968"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=109743"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3967","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in Google Chrome before 17.0.963.46 allows remote\nattackers to cause a denial of service (application crash) via a crafted\ncertificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3967"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=109717"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3966","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in Google Chrome before 17.0.963.46 allows\nremote attackers to cause a denial of service or possibly have unspecified\nother impact via vectors related to error handling for Cascading Style\nSheets (CSS) token-sequence data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3966"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=109716"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3965","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 17.0.963.46 does not properly check signatures, which\nallows remote attackers to cause a denial of service (application crash)\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3965"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=109664"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3964","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 17.0.963.46 does not properly implement the\ndrag-and-drop feature, which makes it easier for remote attackers to spoof\nthe URL bar via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3964"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=109245"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3963","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 17.0.963.46 does not properly handle PDF FAX images,\nwhich allows remote attackers to cause a denial of service (out-of-bounds\nread) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3963"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=109094"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3962","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 17.0.963.46 does not properly perform path clipping,\nwhich allows remote attackers to cause a denial of service (out-of-bounds\nread) via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3962"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=108901"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3961","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRace condition in Google Chrome before 17.0.963.46 allows remote attackers\nto execute arbitrary code via vectors that trigger a crash of a utility\nprocess.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3961"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=108871"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3960","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 17.0.963.46 does not properly decode audio data, which\nallows remote attackers to cause a denial of service (out-of-bounds read)\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3960"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=108416"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3959","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in the locale implementation in Google Chrome before\n17.0.963.46 allows remote attackers to cause a denial of service or\npossibly have unspecified other impact via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3959"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=106441"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-3958","published":"2012-02-09T04:10:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 17.0.963.46 does not properly perform casts of\nvariables during handling of a column span, which allows remote attackers\nto cause a denial of service or possibly have unspecified other impact via\na crafted document.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html","https://www.cve.org/CVERecord?id=CVE-2011-3958"],"bugs":["http://code.google.com/p/chromium/issues/detail?id=105459"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"17.0.963.56~r121963-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"17.0.963.56~r121963-0ubuntu0.11.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.0.963.46","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":70080,"limit":20,"total_results":79316}